How to Change Password in Ubuntu

The Cryptographic Rotation Vector

Maintaining a static login password on an Ubuntu server for prolonged periods mathematically increases the probability of a catastrophic brute-force or dictionary attack breach. If a contractor leaves your organization, or if you suspect a local workstation has been compromised, you must immediately execute a cryptographic rotation. This instructs the Linux kernel to discard your legacy authorization string, generate a new salted hash, and inject it securely into the highly protected `/etc/shadow` registry.

How to Change Password in Ubuntu

The Ubuntu environment utilizes a dedicated, highly secure binary called `passwd` that interacts directly with the shadow registry. It enforces strict authorization checks before permitting any modifications.

1. Open your terminal application or connect to the server via SSH.
2. Method 1: The Self-Rotation Protocol (Changing Your Own Password):
* If you are currently logged into the account you wish to modify, you do not need root privileges.
* Type exactly:
passwd
* Press Enter.
* The Verification Handshake: The kernel must mathematically verify your identity before authorizing the shift. It will prompt: `(current) UNIX password:`
* Type your current legacy password. (Note: Linux will not display asterisks or characters as you type). Press Enter.
* The Cryptographic Injection: The system will prompt: `New password:`
* Type your new, highly secure string. Press Enter.
* The system will prompt: `Retype new password:` (Type it again to confirm).
* If successful, the terminal will return: `passwd: password updated successfully`.
3. Method 2: The Administrative Override (Changing Another User’s Password):
* If you are the server administrator (root) and need to force a password change for a compromised employee account (e.g., a user named “sarah”).
* You must utilize the `sudo` command to invoke master privileges.
* Type exactly:
sudo passwd sarah
* Press Enter and supply your own `sudo` password to authorize the command.
* The Forced Injection: Because you are root, the kernel bypasses the verification handshake. It will not ask for Sarah’s current password. It will immediately prompt: `New password:`
* Type the new string, press Enter, retype it, and press Enter again. The kernel instantly rewrites the `/etc/shadow` file for that specific user.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.