A recent headline in a major news outlet announced, “Please do not change your password” because, as the sub-head teased, “it’s a waste of your time.” The paper cited in the story is the latest salvo questioning a certain orthodoxy about computer security—that strong, cryptic passwords are the keystone to personal security online. This oft-repeated advice may be at best, outdated, and at worst, counterproductive, potentially exposing users to more risk rather than less