<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>password.tooljo.com — blog</title><description>Posts on password entropy, passphrase math, password-storage hashing, and the threat models that drive each.</description><link>https://password.tooljo.com/</link><language>en-us</language><item><title>Why password complexity rules (mostly) make passwords worse</title><link>https://password.tooljo.com/blog/why-password-rules-make-things-worse/</link><guid isPermaLink="true">https://password.tooljo.com/blog/why-password-rules-make-things-worse/</guid><description>Forcing a number, symbol, capital letter, and 90-day rotation produces &apos;P@ssw0rd1!&apos; updated to &apos;P@ssw0rd2!&apos; — same password, lower entropy. NIST changed its mind in 2017. Here&apos;s why most policies haven&apos;t caught up.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>