IELTS Reading · Sentence Completion

The Evolution of Computer Passwords

Read the passage and the 8 Sentence Completion questions below. To attempt the drill, log in free: it opens in the BandLadder test player with instant scoring.
  • 8 questions
  • 770 words
  • About 10 minutes
  • Free account

Reading passage

The Evolution of Computer Passwords

Skip to the questions ↓

In the early decades of electronic computing, access to mainframe hardware was physically restricted, with operators scheduling dedicated blocks of time for individual researchers. As multi-user environments emerged during the 1960s, systems began allowing multiple users to connect simultaneously via remote terminals. This architectural shift necessitated a mechanism to partition storage and safeguard personal files from accidental alteration or unauthorised inspection. Computer scientists addressed the dilemma by borrowing a convention long employed in military sentry posts: the password. Under this initial framework, an operator entered a brief string of text before being granted access to their private workspace. Although elementary, this safeguard functioned adequately in an era when networks were isolated and user communities remained small, collegiate, and largely trustworthy.

Early security systems stored authentication phrases in unencrypted master directories, leaving them vulnerable to anyone capable of inspecting internal system files. To counter this structural weakness, researchers in the mid-1970s developed mathematical routines known as cryptographic hashing functions. Rather than recording the actual characters of a password, the system applied a mathematical algorithm to transform the text into a fixed-length string of alphanumeric characters, termed a digest. When a user attempted to log in, the entered sequence was processed using the identical formula, and the resulting calculation was compared to the stored digest. Because these functions were engineered to be irreversible one-way transformations, obtaining the digest table did not automatically disclose the underlying words.

As computing spread to wider commercial spheres, the human element emerged as the most fragile link in authentication security. People naturally gravitated toward easily remembered sequences, such as personal names, birthdates, or common dictionary terms. System administrators responded by enforcing stringent complexity rules that mandated a combination of uppercase letters, numerals, and special punctuation marks. However, cognitive studies demonstrated that these demands often produced counterproductive outcomes. Users experienced severe cognitive fatigue and routinely adopted predictable coping mechanisms, such as appending an exclamation mark to a familiar word or performing mechanical keyboard walks—tracing adjacent keys across the keyboard layout. Others simply recorded their credentials on physical adhesive notes affixed to computer monitors.

Concurrently, offensive computing techniques expanded in sophistication. Early automated intrusions relied on brute-force algorithms that sequentially tested every possible permutation of characters until finding a match. As computational power increased, attackers deployed dictionary attacks, which fed extensive vocabularies of ordinary words and commonly used substitutes into automated scripts. To accelerate this process, adversaries compiled precomputed databases known as rainbow tables, containing millions of pre-calculated cryptographic digests mapped to potential passwords. In response, system designers introduced a defensive technique known as salting, wherein a unique, randomised string of characters was appended to each password prior to hashing, effectively neutralising the utility of precomputed database lists.

The growing tension between computational vulnerability and human memory prompted a fundamental reassessment of password design principles. For decades, security guidance had prioritised character complexity over overall length, encouraging short strings packed with confusing symbols. Statistical analysis eventually demonstrated that this approach was flawed. A relatively short string, even with varied symbols, offers far fewer total mathematical combinations than a longer sequence composed of several ordinary words strung together. This revelation popularised the concept of the passphrase—a connected series of distinct vocabulary items. Passphrases provide vastly greater mathematical entropy, making them resilient against automated guessing while remaining comparatively effortless for human users to recall without resorting to written aids.

Despite enhancements in password construction, the inherent limitations of relying on static shared secrets became increasingly apparent. Breaches at major web services regularly leaked billions of stored credentials onto illicit markets, enabling automated credential stuffing attacks against unrelated platforms. Consequently, institutions began implementing multi-factor authentication, requiring users to furnish secondary verification alongside their primary secret. This secondary layer often involves a temporary numerical token sent to a mobile device, a physical security key inserted into a port, or biometric indicators such as fingerprint patterns. By requiring confirmation across multiple independent channels, systems ensure that intercepted passwords alone are insufficient to compromise an account.

Today, the technological trajectory is moving decisively toward eliminating passwords entirely. Emerging open standards rely on asymmetric public-key cryptography to authenticate users without transferring any secret phrase across the network. Under this paradigm, a user’s device generates a linked pair of cryptographic keys: a public key stored on the host server and a private key securely sequestered within the local hardware. When authentication is requested, the server issues a digital challenge that can only be resolved by the private key, which is unlocked locally through facial recognition or a physical touch. Because the private key never leaves the individual device, remote phishing and database theft are rendered fundamentally obsolete.

Questions 1–8

Complete the sentences below. Choose NO MORE THAN TWO WORDS from the passage for each answer.

Word limit: NO MORE THAN TWO WORDS

  1. 1Early time-sharing systems allowed numerous people to access mainframes at the same time using .

  2. 2Mathematical algorithms were introduced to convert passwords into an alphanumeric string referred to as a .

  3. 3Under strict complexity mandates, individuals often traced neighbouring buttons in habits known as .

  4. 4Attackers created precalculated collections of data called to speed up their cracking attempts.

  5. 5The protective practice of involves attaching random characters to passwords to foil automated database matching.

  6. 6Combining several distinct words into a passphrase yields much higher than using short strings of complex symbols.

  7. 7Stolen user details sold online frequently permitted automated across different online services.

  8. 8In passwordless frameworks, a host server verifies identity by presenting a that local hardware must solve.

Ready to answer these 8 questions?

Log in to attempt this drill in the BandLadder test player, with instant scoring when you finish.

Ready for a full Reading test?

Three passages, 40 questions of every type and 60 minutes on the clock, with your band score the moment you finish. Your free account also gets AI-scored Writing and Speaking.

Take a full timed test free →

Keep practising

More Sentence Completion drills

Get your band, not just a score

  • ✓Full timed Reading and Listening tests
  • ✓AI-scored Writing with band feedback
  • ✓AI-scored Speaking with an AI examiner
Take a full timed test free

Free account · no card

© 2026 BandLadder. Written and checked by the BandLadder team. You may quote or cite this page with credit to BandLadder and a link to it; republishing it in full needs our written permission. Content use policy

Log in to attempt — free