Bill Burr recommended literature phrases as passwords.

Bill Burr worked as a mid-level manager at the National Institute of Standards and Technology (NIST) in 2003. He was in charge of writing information security guidelines, specifically the section on passwords. He's the man responsible for the complex rules users had to follow while creating a password. But during a 2017 Wall Street Journal interview, he admitted, "Much of what I did I now regret." Since Burr retired, the guidelines have been updated, but the majority of internet users still follow Burr's rules.
Burr spoke to Rosemary Barton, the host of CBC's "As It Happens," and said, "The effect of the advice that I gave on passwords, it wasn't what I had intended, and it tends to drive people crazy. But on the other hand, I'm not the only one giving that kind of advice, so I don't deserve the entire blame for this." His advice back in 2003 was to use numbers and special characters while creating their passwords. He also advised users to change them every three months. However, Burr clarified that the rules were never meant for ordinary people. They were written specifically for security administrators.

Over the years, the rules did little to improve password security. Because of the complex guidelines, people ended up with silly passwords. When it was time to change them, they tended to repeat the same password followed by a consecutive number. "Those things are pretty predictable, and I probably should have anticipated, because that's what I've wound up doing, actually, in some cases," Burr admitted.
Over the years, hackers have found different ways to get the information and passwords they want. What is Burr's latest advice to prevent hackers from getting your information? "Pick a reasonable password and use two-step authentication for things that really matter a lot. For things that don't matter so much, maybe not." His personal preference is phrases from literature.
Forbes Advisor conducted a poll and asked users how they come up with their passwords. 42% revealed that they used numbers and words that meant something to them, 34% created passwords depending on the requirements, while 32% mixed and matched words and numbers, similar to the way Burr recommended. While 18% admitted that they just refreshed an old password, also similar to what Burr predicted. Additionally, the respondents revealed the main reasons their passwords were compromised. 35% revealed they had weak passwords, and 30% of the respondents repeated their passwords.
Paul Grassi, a NIST standards-and-technology adviser, helped to rewrite the password guidelines. They had to begin from scratch and removed the 90-day expiration date. They also removed the need to use special characters. The new rule was to use long and easy-to-remember passwords, instead of jumbled special characters and numbers. Despite the new guidelines, several websites have yet to adopt them and still follow Burr's special character rules.
Security experts say it's time to stop using complicated passwords as they make you less safe
Gen Z have worse passwords than Boomers and Millennials despite growing up in the digital age