I keep a note in my phone with thirty-seven passwords I’ve forgotten and reset at least twice. Somewhere in that list is the email account I use to reset other passwords, which itself requires a password I’ve definitely written on a Post-it note that may or may not still be stuck to my desk. This is not how anyone intended things to go.

The password was supposed to be temporary. In 1961, a computer scientist at MIT needed a quick way to keep users from reading each other’s files on a shared machine. He built a simple login system, assumed someone would replace it with something better, and moved on. Sixty years later, we’re still using his stopgap—and everyone agrees it’s a disaster.

Passwords have outlived their shelf life, which is why so many people now offload them entirely — Comparisony compares 1Password vs. Bitwarden, and CISA’s Secure Our World guidance covers current password best practices.

The short answer

Passwords were created in 1961 at MIT as a side effect of computer time-sharing. They were never designed to scale to billions of users or protect sensitive data. We’re stuck with them because replacing every password-based system on Earth would require a level of coordination that has yet to happen.

The accidental invention: MIT and the first passwords

Fernando Corbató didn’t set out to invent the password. He was trying to solve a scheduling problem.

In 1961, computers were the size of rooms and cost as much as houses. MIT’s Computation Center had one machine—the Compatible Time-Sharing System, or CTSS—and a growing list of researchers who wanted to use it. Corbató’s team built a system that let multiple people log in at once, each with their own files and settings. The problem: anyone could open anyone else’s files just by typing the right command.

The solution was obvious and inelegant. Each user would pick a four-to-six-character word. The system would ask for it at login. If you typed the right word, you got in. If you didn’t, you didn’t.

These first passwords were stored in plain text on the machine’s disk. No encryption, no hashing, no expiration dates. This wasn’t carelessness—the computer lived in a locked room, accessible only to a small group of trusted researchers. The idea that millions of strangers would someday use passwords to access bank accounts from coffee shops would have sounded like science fiction.

Before computers: When secrets needed protecting

Large vintage mainframe computer system in a 1960s computer center room
Photo by panumas nikhomkhai on Pexels

The concept of a secret phrase granting access is older than CTSS by a few thousand years. Roman soldiers used signums—daily passwords—to identify each other at night. Medieval castles had challenge-and-response phrases to verify messengers. Cold War military communication relied on one-time pads and classified codes.

These were the cybersecurity origins of password thinking, even if no one called it that. The pattern was always the same: prove you know the secret, gain access to the protected thing.

But computer passwords were different in one critical way. A Roman soldier’s signum changed daily and was only shared among a small group. A computer password, once set, could sit unchanged for months or years—and the system had to remember it for every user, all the time. That meant storing secrets in a way that was both accessible (the computer needed to check them) and secure (no one else should see them). Those two goals turned out to be nearly impossible to balance.

The moment everything broke: The Morris Worm and password creation rules

For two decades, passwords hummed along quietly. They weren’t perfect, but they worked well enough for universities and research labs. Most people didn’t have a computer. The ones who did treated passwords like they treated office keys—simple, memorable, rarely changed.

Then came November 2, 1988.

A graduate student named Robert Tappan Morris released a worm—a self-replicating program—onto the early Internet. It wasn’t meant to be destructive; Morris later said he wanted to measure the size of the network. But the worm had a bug. It spread faster than intended, infecting roughly 6,000 computers—about ten percent of the Internet at the time—and grinding many of them to a halt.

The worm’s success came down to passwords. It exploited weak and reused passwords on Unix systems, guessing common words and phrases until it found a match. The breach exposed what security experts had quietly worried about for years: passwords that worked fine in a locked room became catastrophic vulnerabilities at scale.

The response was swift and, in hindsight, misguided. Institutions began mandating “strong” passwords: at least eight characters, mixing uppercase and lowercase letters, including numbers and symbols, changed every 90 days. In 2003, the National Institute of Standards and Technology formalized these rules in official guidance. Banks, email providers, and workplaces adopted them as gospel.

The theory was sound. The practice was a mess. Users, forced to create passwords they couldn’t remember, did exactly what you’d expect: they wrote them on Post-its, reused slight variations across accounts (Password1, Password2, Password3), and substituted characters in predictable ways (@ for a, 3 for E, ! at the end). Security decreased. Frustration increased.

The rule that backfired

Stone gateway entrance to a medieval castle fortress
Photo by Scott Precious on Pexels

In 2017, NIST quietly reversed itself.

The agency’s updated guidance admitted that forced complexity and regular password changes actually made systems less secure. Predictable substitutions were easy for automated cracking tools to guess. Frequent resets encouraged weak, recycled passwords. The whole edifice of “strong password” rules—the thing we’d spent fifteen years training users to follow—had backfired.

The better approach, researchers found, was longer passphrases: random words strung together, easy for humans to remember, hard for computers to crack. “Correct horse battery staple” beats “P@ssw0rd!” by every measure that matters.

But by then, millions of systems were already built around complexity rules. Changing them would mean retraining users, updating legacy software, convincing security teams to abandon standards they’d enforced for years. Hardly anyone did. We knew the rules were broken. We kept following them anyway.

What it means: Why we’re still stuck

Passwords dominate because replacing them requires everyone to switch at once. A bank can’t adopt fingerprint-only login if half its customers use older devices without biometric readers. An email provider can’t drop passwords entirely if third-party apps still rely on them. A workplace can’t move to hardware security keys if employees work remotely across a dozen countries with inconsistent shipping.

The irony is that better alternatives exist and have existed for decades. Fingerprint readers appeared in the 1980s. Smart cards in the 1990s. Hardware security keys in the 2010s. Passkeys and biometric authentication are available on most new devices right now. But “available” and “universally adopted” are separated by years of infrastructure overhaul that no one wants to fund.

So we’ve built elaborate workarounds instead. Two-factor authentication. Password managers. Biometric unlock paired with a password backup. These help, but they don’t solve the underlying problem—they just add layers on top of a foundation we know is cracking.

The average person now juggles over a hundred passwords. They forget a quarter of them. They reuse half across multiple sites. And when a breach happens—which it does, regularly—millions of credentials spill onto the Internet at once, starting the cycle over again.

FAQ

When were passwords first created?

The first computer passwords appeared in 1961 on MIT’s Compatible Time-Sharing System (CTSS). Earlier forms existed in military and diplomatic contexts, but the modern password as a login credential originates with CTSS.

Who invented the password?

Fernando Corbató and his team at MIT’s Computation Center developed the password system for CTSS. Corbató has said it was meant as a temporary fix, not a permanent solution.

What was the first computer password?

There’s no record of the literal first password typed into CTSS. The system allowed four-to-six-character passwords stored in plain text, but individual user choices weren’t documented.

Why do we still use passwords if they’re insecure?

Path dependence. Once millions of systems were built around passwords, switching to alternatives became prohibitively expensive and logistically complex. Replacing them would require coordinated action across industries, device manufacturers, and billions of users.

How have password rules changed over time?

Early passwords were short and simple. After the 1988 Morris Worm, complexity rules became standard: uppercase, numbers, symbols, regular changes. In 2017, NIST reversed course, recommending longer passphrases instead and dropping forced expiration. Many systems still use the old rules.


The password will eventually disappear. Passkeys are creeping into operating systems. Biometrics are normalizing. But “eventually” has meant “five years away” since 2015, and I’m not holding my breath. In the meantime, I’ve got another password reset email to deal with.