Why is changing your password regularly not a good idea?

One of the most enduring pieces of password security knowledge is that changing your passwords regularly increases security. At least, that's what IT teams around the world have been pushing on people for decades.

However, that advice has always been met with resistance. Many in the security industry argue that this leads to passwords that are easy to remember. Now, research has proven this theory, demonstrating that frequently changing passwords can lead to security problems.

Changing passwords frequently leads to poor security

Many of us find mandatory password changes every 4, 6, or 8 weeks intimidating. One IT group promotes the idea that changing your password will make any security breaches irrelevant, since everyone will use new passwords.

Why is changing your password regularly not a good idea?

In practice, this leads to weaknesses in password creation. Instead of creating strong, unique, and hard-to-guess passwords, most people choose passwords that are easy to remember with small, repeated parts.

For example, a strong 16-character password might be "hS'9{yX?Fzu#=_:R", which includes a mix of uppercase and lowercase letters, numbers, and symbols. It's hard to remember, but over time, you'll get the hang of it. Whereas if you had to change your password every month, you wouldn't have time to remember it. So people started using easier-to-remember phrases with small, repeated parts.

  • January: difficultpassword1
  • February: d1fficultpassword2
  • March: d1ff1cultp4ssword3
  • V,v...

Choose strong, unique passwords (or use a password manager)

The UK's National Cyber ​​Security Centre has recommended against using regular passwords since 2015, and now, in 2024, the National Standards Institute is following suit.

Their new advice recommends passwords expire every 365 days, significantly changing the timeframe — and increasing security.

At the same time, NIST is also updating its messaging on password length and strength. In some cases, password creation rules limit users to 12 characters or prevent certain symbols from being used. NIST now recommends that all passwords:

  • Minimum 15 characters
  • Maximum 64 characters
  • Includes all ASCII characters, whitespace characters, and Unicode characters

These changes mean more password entry fields will allow for stronger and more memorable passphrases, while overall password strength is also increased.

Of course, any organization that cares about password security should enable the use of a password manager. There are additional security considerations involved with using a password manager, such as local data storage, zero-knowledge encryption, etc., but it's a best practice to protect all of your accounts with strong passwords.

Leave a Comment

What Young Riders Should Know About Moving Their Motorcycles Across Cities

What Young Riders Should Know About Moving Their Motorcycles Across Cities

Long-distance travel can involve heavy traffic, changing weather conditions, and rider fatigue. If you are also dealing with the responsibilities of moving home, such as packing belongings or coordinating accommodation, a long ride may add unnecessary pressure to an already busy schedule.

Solving Microsoft Teams Shortcut Error Not Opening

Solving Microsoft Teams Shortcut Error Not Opening

Tired of Microsoft Teams shortcut error preventing you from opening the app? Follow our expert, step-by-step guide with the latest fixes for instant resolution. Works on Windows, Mac & web – no tech skills needed!

Solving Microsoft Teams Task Management Sync Error

Solving Microsoft Teams Task Management Sync Error

Tired of Microsoft Teams Task Management Sync Error halting your workflow? Follow our proven, step-by-step fixes to resolve sync issues fast and restore seamless task collaboration. No tech expertise needed!

Troubleshooting Microsoft Teams Wiki Error Formatting

Troubleshooting Microsoft Teams Wiki Error Formatting

Struggling with Microsoft Teams Wiki Error Formatting? This step-by-step guide reveals proven fixes for common wiki tab issues, ensuring smooth editing and collaboration in Teams. Get back to productive wikis fast!

How to Fix Microsoft Teams Installation Error for Linux

How to Fix Microsoft Teams Installation Error for Linux

Struggling with Microsoft Teams installation error on Linux? Discover step-by-step fixes for Ubuntu, Fedora & more. Resolve dependency issues, crashes, and errors quickly with our ultimate guide. Get Teams running smoothly today!

Solving Microsoft Teams Error Page Not Loading

Solving Microsoft Teams Error Page Not Loading

Struggling with Microsoft Teams "Error Page" not loading? Get step-by-step fixes for desktop, web, and mobile. Solve Microsoft Teams Error Page issues quickly and resume seamless teamwork today.

Solving Microsoft Teams Error Screenshot Issues

Solving Microsoft Teams Error Screenshot Issues

Tired of Microsoft Teams "Error Screenshot" blocking your workflow? Get proven, step-by-step solutions to resolve screenshot errors in Teams instantly and boost productivity. No tech skills needed!

How to Fix Microsoft Teams Error U User

How to Fix Microsoft Teams Error U User

Tired of Microsoft Teams "Error U" User blocking your chats? Get proven, step-by-step fixes to clear cache, reset, and restore seamless collaboration instantly.

Where are Microsoft Teams Registry Keys Located on Windows 11?

Where are Microsoft Teams Registry Keys Located on Windows 11?

Unlock the precise locations of Microsoft Teams registry keys on Windows 11. Step-by-step guide to find, access, and safely tweak them for optimal performance and troubleshooting. Essential for IT pros and Teams enthusiasts.

How to Fix Microsoft Teams Training Error Video Lag

How to Fix Microsoft Teams Training Error Video Lag

Tired of Microsoft Teams "Training Error" Video Lag ruining your meetings? Follow our step-by-step guide with the latest fixes for smooth video calls—no more frustration!