Skip to main content

Password Fatigue - The Burden of Too Many Passwords

About 2 min read

Password fatigue refers to the psychological burden and weariness that arise from the ever-increasing number of passwords people must manage in daily life and at work. NordPass research put the average number of personal passwords one person manages at 168 in 2024, an all-time high, and at roughly 120 personal plus 67 work-related passwords in its 2026 study. Even at the lower figure, setting and memorizing a different strong password for each one exceeds the limits of human cognitive ability. This sense of fatigue induces risky behaviors such as reusing or simplifying passwords, increasing vulnerability to attacks like credential stuffing.

The Growth in Account Numbers and Cognitive Limits

In the early 2000s, a typical user managed only a handful of online accounts. However, with the explosive spread of SaaS, the rise of subscription services, and the diversification of work tools, the number of credentials one person has to juggle grew sharply during the 2020s. As the NordPass figures cited above show, the average number of personal passwords is on the order of three digits. People can reliably recall only a very small number of passwords, so setting and remembering a unique, strong password for accounts on that scale is not realistic without supporting tools.

80
168
120
202020242026

Average number of personal passwords per person (from NordPass research)

Risky Behaviors Caused by Password Fatigue

Password fatigue is not merely an inconvenience; it directly leads to concrete security risks. Fatigued users unconsciously adopt behaviors such as the following.

Reuse

Reusing the same password across multiple services. A single breach cascades to every account.

Simplification

Prioritizing memorability and setting weak passwords like "password123." They are cracked instantly by a brute-force attack.

Writing It Down

Recording passwords on sticky notes or in spreadsheets. This creates the risk of physical shoulder surfing or file leakage.

The concrete risks of password reuse are explained in detail in the article on the dangers of password reuse.

Relief Through Password Managers

A password manager is the most practical solution to password fatigue. By memorizing just one master password, you can automatically generate and autofill a unique, random password for each service. Users are freed from the cognitive load of "remembering passwords" and can achieve both security and convenience. With a password manager, even the complex requirements demanded by a password policy become painless.

A Fundamental Solution Through Passkeys

A passkey is a technology that removes the need for passwords altogether, and it is the most fundamental way to address password fatigue. Because you sign in with fingerprint or facial authentication, there is no per-service password to memorize. Since the service never stores a password, there is nothing to reuse, nothing to leak, and nothing to type into a fake site. What protects a passkey, however, is the lock screen of your device, so you still need to arrange your own recovery path for a lost device or a phone upgrade (the account you sync to, or a backup authentication method). As of 2025, support is spreading outward from the largest services, so passkeys and passwords will coexist for some time.

Steps to Resolve Password Fatigue

Adopt a password manager
Make existing passwords unique
Migrate passkey-enabled services
Go passwordless

The Relationship with Security Fatigue

Password fatigue is part of the broader concept of security fatigue. Security fatigue refers to weariness toward security measures in general, including frequent demands to change passwords, the hassle of multi-factor authentication, and the sheer number of security alerts. In its 2017 guideline revision, NIST (the U.S. National Institute of Standards and Technology) deprecated the forced periodic changing of passwords. This reflects research findings that security fatigue can actually lower security. The article on security fatigue explains countermeasures at the organizational level in detail.

Real-World Use Cases

It is common, for example, for an internal help desk to find that password reset requests fill up its queue. The cause is not careless users but the practice itself of asking people to memorize a new password every time another business tool is added. In that situation, issuing a password manager at the company level, so that the only things employees have to remember are the master password and their device unlock, makes reset requests fall away on their own. The order is the same for individuals: guard just two things with your own memory, your email account and your password manager, and leave the rest to generated, unique passwords. That is the shortest route to lightening the memory load.

The psychological aspects of passwords are explained in detail in the article on password psychology.

Related Terms

Was this article helpful?