Passwords for children: what to teach before the first real account
Password education for children is mostly inherited folklore from corporate IT circa 2005: mandatory symbols, regular changes, complexity theatre. Modern guidance β NIST's landmark 2017 revision (SP 800-63B) and the UK NCSC's aligned advice β retired much of that, because the data on real breaches showed where passwords actually fail. Teaching children the old rules wastes their goodwill on rituals; teaching how failure actually happens builds judgment that lasts.
How passwords actually fail (and what that implies)
Breach analyses converge on a ranking that surprises most adults:
- Reuse is the biggest killer. Credentials leak from some breached service, then get replayed everywhere ("credential stuffing"). The strongest password in the world protects nothing if it's the same one everywhere. β One secret per door is the highest-value rule there is.
- Phishing beats complexity. A password typed into a fake page is captured regardless of its symbols (the recognition skills matter more than the character set β and "no real service asks for your secret by message" is the password rule and the phishing rule in one).
- Guessing succeeds against human patterns, not length: dictionary words + "1!" transformations, pet names, birthdays β attackers guess what people do. β Length beats cleverness: NIST/NCSC's shift to favoring long memorable passphrases (three or four random words) over short symbol-salad reflects the arithmetic β length grows strength exponentially; ritual substitutions (aβ@) add almost nothing because crackers know every ritual.
- Forced periodic change made things worse β people responded with Password1 β Password2. NIST now recommends against routine expiry (change on compromise, not on calendar).
Sharing sits outside the technical ranking but dominates the child-sized threat model: for primary-aged children, the realistic "attacker" is a classmate with their secret β which is why the social rule matters most of all.
What to teach, by developmental stage
- Before text passwords (roughly FβYear 2): the concept of a secret that lets the computer know it's you β via age-appropriate mechanisms (picture sequences, PINs). The teachable core is entirely social: your secret is yours; no one is entitled to it; asking for someone's secret is like asking for their toothbrush.
- Middle primary: the toothbrush rules harden (never share β not best friends, not for fairness; a teacher can reset, which is why they never need to know), plus the first mechanics: secrets are typed hidden, never written where others read, never said aloud.
- Upper primary: passphrases ("three funny words beat one clever word β
walrus-piano-toast"), one-per-door with the reuse story told honestly, "no real service asks for it by message," and β as real accounts arrive β that password managers and family processes exist so nobody has to memorize twenty doors.
What the evidence doesn't say
- It doesn't support complexity rituals for children β a symbol requirement on a nine-year-old's account produces
Dragon1!on a sticky note, the worst of every world. - It doesn't make sharing-with-parents wrong at this age β family visibility of a young child's credentials is a safety judgment for families, distinct in kind from peer-sharing; conflating them confuses children.
- It doesn't say children need adult-grade threat models β the ranked failures above are background for the teacher; the child needs the rules and the why at their size.
In the classroom
- Teach the toothbrush rules before any mechanics β the social layer is where child accounts actually fail.
- When passwords arrive, teach passphrases and skip the symbol theatre entirely; you'll be teaching current NIST/NCSC guidance rather than 2005's.
- Tell the reuse story once, vividly (one leaked door opens every door) β it's the single most protective concept they'll carry to adolescence.
- Rehearse the reset path: knowing "I tell my teacher and it gets reset, no trouble" prevents both the sticky note and the concealed lockout.
How Wiz Kids applies this
Student authentication is a picture-sequence secret β age-appropriate mechanics with the full social curriculum attached (our first safety lesson is precisely the best-friend-asks scenario, toothbrush metaphor included), and teachers reset seats without ever knowing secrets, modelling the reset-not-reveal principle. There's deliberately no password complexity theatre anywhere: the architecture keeps stakes low while the habits β secrets stay secret, adults reset rather than know, no service asks by message β are rehearsed until they're reflexes ready for the first real account. (Why picture passwords β the design memo.)
References
- NIST (2017, updated). Special Publication 800-63B: Digital Identity Guidelines β Authentication and Lifecycle Management β the modern baseline: length over complexity, no routine expiry, screen against known-breached lists.
- UK National Cyber Security Centre β Three random words guidance and password policy advice.
- Verizon Data Breach Investigations Report (annual) β the credential-reuse and phishing failure rankings.
- Bonneau, J., Herley, C., van Oorschot, P. C., & Stajano, F. (2012). The quest to replace passwords. IEEE Symposium on Security and Privacy β why passwords persist and what actually improves them.
Β© Glu IO Pty. Ltd. β Wiz Kids (wiz.kids). Link freely; republication requires permission β see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.