πŸ§™ Wiz Kids
Learn β€Ί Online Safety & Digital Citizenship

Passwords for children: what to teach before the first real account

Evidence grade: STRONG on how passwords fail and modern guidance; THIN on child-specific studies β€” so the child-facing advice here is well-grounded security engineering translated to developmental reality, and labelled as such.

Password education for children is mostly inherited folklore from corporate IT circa 2005: mandatory symbols, regular changes, complexity theatre. Modern guidance β€” NIST's landmark 2017 revision (SP 800-63B) and the UK NCSC's aligned advice β€” retired much of that, because the data on real breaches showed where passwords actually fail. Teaching children the old rules wastes their goodwill on rituals; teaching how failure actually happens builds judgment that lasts.

How passwords actually fail (and what that implies)

Breach analyses converge on a ranking that surprises most adults:

  1. Reuse is the biggest killer. Credentials leak from some breached service, then get replayed everywhere ("credential stuffing"). The strongest password in the world protects nothing if it's the same one everywhere. β†’ One secret per door is the highest-value rule there is.
  2. Phishing beats complexity. A password typed into a fake page is captured regardless of its symbols (the recognition skills matter more than the character set β€” and "no real service asks for your secret by message" is the password rule and the phishing rule in one).
  3. Guessing succeeds against human patterns, not length: dictionary words + "1!" transformations, pet names, birthdays — attackers guess what people do. → Length beats cleverness: NIST/NCSC's shift to favoring long memorable passphrases (three or four random words) over short symbol-salad reflects the arithmetic — length grows strength exponentially; ritual substitutions (a→@) add almost nothing because crackers know every ritual.
  4. Forced periodic change made things worse β€” people responded with Password1 β†’ Password2. NIST now recommends against routine expiry (change on compromise, not on calendar).

Sharing sits outside the technical ranking but dominates the child-sized threat model: for primary-aged children, the realistic "attacker" is a classmate with their secret β€” which is why the social rule matters most of all.

What to teach, by developmental stage

What the evidence doesn't say

In the classroom

  1. Teach the toothbrush rules before any mechanics β€” the social layer is where child accounts actually fail.
  2. When passwords arrive, teach passphrases and skip the symbol theatre entirely; you'll be teaching current NIST/NCSC guidance rather than 2005's.
  3. Tell the reuse story once, vividly (one leaked door opens every door) β€” it's the single most protective concept they'll carry to adolescence.
  4. Rehearse the reset path: knowing "I tell my teacher and it gets reset, no trouble" prevents both the sticky note and the concealed lockout.

How Wiz Kids applies this

Student authentication is a picture-sequence secret β€” age-appropriate mechanics with the full social curriculum attached (our first safety lesson is precisely the best-friend-asks scenario, toothbrush metaphor included), and teachers reset seats without ever knowing secrets, modelling the reset-not-reveal principle. There's deliberately no password complexity theatre anywhere: the architecture keeps stakes low while the habits β€” secrets stay secret, adults reset rather than know, no service asks by message β€” are rehearsed until they're reflexes ready for the first real account. (Why picture passwords β€” the design memo.)

References


Β© Glu IO Pty. Ltd. β€” Wiz Kids (wiz.kids). Link freely; republication requires permission β€” see terms. Found an error in our reading of the research? We correct fast: tell any teacher piloting Wiz Kids.