Why is changing your password regularly not a good idea?

One of the most enduring pieces of password security knowledge is that changing your passwords regularly increases security. At least, that's what IT teams around the world have been pushing on people for decades.

However, that advice has always been met with resistance. Many in the security industry argue that this leads to passwords that are easy to remember. Now, research has proven this theory, demonstrating that frequently changing passwords can lead to security problems.

Changing passwords frequently leads to poor security

Many of us find mandatory password changes every 4, 6, or 8 weeks intimidating. One IT group promotes the idea that changing your password will make any security breaches irrelevant, since everyone will use new passwords.

Why is changing your password regularly not a good idea?

In practice, this leads to weaknesses in password creation. Instead of creating strong, unique, and hard-to-guess passwords, most people choose passwords that are easy to remember with small, repeated parts.

For example, a strong 16-character password might be "hS'9{yX?Fzu#=_:R", which includes a mix of uppercase and lowercase letters, numbers, and symbols. It's hard to remember, but over time, you'll get the hang of it. Whereas if you had to change your password every month, you wouldn't have time to remember it. So people started using easier-to-remember phrases with small, repeated parts.

  • January: difficultpassword1
  • February: d1fficultpassword2
  • March: d1ff1cultp4ssword3
  • V,v...

Choose strong, unique passwords (or use a password manager)

The UK's National Cyber ​​Security Centre has recommended against using regular passwords since 2015, and now, in 2024, the National Standards Institute is following suit.

Their new advice recommends passwords expire every 365 days, significantly changing the timeframe — and increasing security.

At the same time, NIST is also updating its messaging on password length and strength. In some cases, password creation rules limit users to 12 characters or prevent certain symbols from being used. NIST now recommends that all passwords:

  • Minimum 15 characters
  • Maximum 64 characters
  • Includes all ASCII characters, whitespace characters, and Unicode characters

These changes mean more password entry fields will allow for stronger and more memorable passphrases, while overall password strength is also increased.

Of course, any organization that cares about password security should enable the use of a password manager. There are additional security considerations involved with using a password manager, such as local data storage, zero-knowledge encryption, etc., but it's a best practice to protect all of your accounts with strong passwords.

Sign up and earn $1000 a day ⋙

Leave a Comment

What is SpicyChat AI?

What is SpicyChat AI?

SpicyChat AI is an enhanced form of classic role-playing chat where interaction takes place through avatars or characters using Artificial Intelligence (AI).

Warning signs you may be lactose intolerant

Warning signs you may be lactose intolerant

Lactose intolerance occurs in people who lack the enzyme needed to break down lactose, the sugar in milk. Here are common signs of lactose intolerance.

The Best Diets for Heart Health

The Best Diets for Heart Health

In addition to regular exercise and not smoking, diet is one of the best ways to protect your heart. Here are the best diets for heart health.

How to turn off the Save As to OneDrive option on Microsoft 365

How to turn off the Save As to OneDrive option on Microsoft 365

Microsoft 365 apps provide direct access to OneDrive. If you don't use OneDrive, you can remove this option from Office 365 when saving a file.

Latest Ninja Tien Len Code and how to enter code

Latest Ninja Tien Len Code and how to enter code

Ninja Tien Len Giftcode is released by the game developer to support initial players.

US users can now access ChatGPT via 1-800-CHATGPT

US users can now access ChatGPT via 1-800-CHATGPT

With just a quick call to 1-800-CHATGPT, you can now chat with this AI assistant.

Why use Llama 3.2 instead of ChatGPT?

Why use Llama 3.2 instead of ChatGPT?

Amidst all the AI ​​hype, Llama 3.2 is a gentle option that pays attention to the finer details and it's time you switched to this tool.

How to take a screenshot on Samsung Galaxy

How to take a screenshot on Samsung Galaxy

Taking screenshots on Samsung Galaxy phones is also extremely easy.

How to insert and remove watermark in Word document

How to insert and remove watermark in Word document

To insert or remove watermark on Word document, we can immediately use the available feature in this editing tool, with 2 different ways to insert watermark in the content.

What is the best AI photo background remover?

What is the best AI photo background remover?

People spend too much time manually removing backgrounds, and AI isn't always the magic it claims to be.

SpaceX launches first mobile satellite supporting direct connection to smartphones

SpaceX launches first mobile satellite supporting direct connection to smartphones

On January 3, Elon Musk's SpaceX launched the first six satellites that can provide mobile service to remote areas without the need for a terminal.

NVIDIA GeForce RTX 5060 Ti Officially Launched: Blackwell GB206 GPU, 20% More Performance Than RTX 4060 Ti And Twice As Fast When Using DLSS 4

NVIDIA GeForce RTX 5060 Ti Officially Launched: Blackwell GB206 GPU, 20% More Performance Than RTX 4060 Ti And Twice As Fast When Using DLSS 4

NVIDIA's next flagship graphics card, the GeForce RTX 5060 Ti, will come in 16GB and 8GB versions and is expected to launch in mid-April.

Cybercriminals are spreading malware using... Google Search

Cybercriminals are spreading malware using... Google Search

A new attack campaign that spreads malware through Google search results has been discovered by security experts from Palo Alto Networks.

Google adds feature to automatically open apps after installation on Play Store

Google adds feature to automatically open apps after installation on Play Store

Google is adding a small but long-awaited new feature to the Play Store.

High salary but no work required, how Tim Cook retains talent

High salary but no work required, how Tim Cook retains talent

After Tim Cook took over as CEO in 2011, in an effort to maintain public trust in Apple, he retained senior employees by paying them without requiring them to work.