Changing Passwords Periodically Doesn’t Increase Security

Does your organization or some financial website require you to create a new password periodically? This practice was recommended long ago, but some organizations haven’t kept up with current recommendations that discourage such policies. If you’re bound by a password expiration policy, you can use this article to encourage your IT department or financial institution to update its approach to password security.

The rationale behind password expiration policies was that if an attacker were to steal a password database and decrypt some passwords, they would work for only a limited period, lessening the risk of unauthorized access. Even if an attacker gained access to an account, they could remain undetected only if they didn’t change the password, and that access wouldn’t last indefinitely.

Over time, security experts realized that the problem wasn’t so much how long an attacker could remain undetected but allowing users to set weak passwords that could be decrypted. It turns out that users often choose weaker passwords when they know they will have to change them, perhaps by tweaking a previous password for easier memorization. This fact hasn’t been lost on attackers, making it easier for them to figure out future passwords. In other words, attempting to increase security by requiring users to change passwords paradoxically reduces security.

The National Institute for Standards and Technology (NIST) is a US government agency that develops cybersecurity standards and best practices for the federal government that large corporations and other institutions tend to follow. In 2017, NIST changed its guidelines to say, “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).” In a FAQ, NIST explains:

Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets have been compromised since attackers can apply these same common transformations.

Of course, if there’s evidence of unauthorized access or a breach of the password database, all passwords should be invalidated and everyone should be required to create a new password immediately—that’s entirely different than requiring passwords to be changed on a schedule.

Interestingly, NIST also doesn’t recommend password composition requirements—such as requiring the password to contain a letter, number, and special character—because users tend to devise predictable techniques to meet such requirements, such as appending an exclamation point to every password. Instead, NIST encourages longer passwords because a long password that’s easily remembered and typed can be stronger than a shorter password composed of random characters. Password managers can generally create both types.

If you’re forced to change a website password periodically, it’s easiest to use a password manager to generate and enter a new strong password, and you won’t have to memorize the new password. For the very few passwords you must remember and type manually, aim for longer passwords that won’t trip up your fingers while typing or require numerous switches of iPhone uppercase and numeric keyboards. To aid memorization, perhaps consider choosing words for your password from categories with many possibilities. For instance, if your initial password is gouda-purple-1989-New-York, the next one could be cheddar-black-2011-Des-Moines. Both are strong in their own right, but only you would know the categories used for each portion.

(Featured image based on an original by iStock.com/designer491)


Social Media: Security experts no longer recommend password expiration policies that require users to change their passwords periodically. Here’s why.

Similar Posts

  • Missed an Alert? Check Notification Center

    iOS, iPadOS, and macOS all let you specify whether any given app should show no notifications, temporary banners, or persistent alerts: look in…

  • Spring Fever

    We’re all starting to chat the itch to spend some more time outside around the office. Most of us enjoy winter activities throughout the winter months, but we are coming out of one of the worst winters in a long time. There was little snow and many winter activities were cancelled over the past several months. To help get us out of the winter funk, we thought it was appropriate to celebrate “**Spring Fever**”:http://www.smalldog.com/springfever/spring-fever in our stores by putting together some great deals for accessories that you can use to enjoy the warmer weather that is upon us.

    Recently we have brought in products from several new manufacturers of speakers, headphones and iPhone accessories. One of my favorite new items that we have brought in are new “**Bluetooth speakers from Cambridge Audio**”:http://www.smalldog.com/product/87874/. These portable speakers come in a variety of colors, they easily sync to both your computer and iPhone (though not at the same time) and they have an auxiliary connection if you wish to plug the speaker directly into your device. We’ve all been impressed by the ease of pairing the speakers as well as the sound quality. These speakers normally sell for $99.99 but we have the titanium colored ones on sale for **79.99**. They are an excellent quality at this price point. Last week I introduced new Bluetooth headphones from “**BlueAnt**”:http://www.smalldog.com/category/?mmfg%5B0%5D=BlueAnt and we’ve decided to bundle these headphones with a **FREE** Belkin armband for iPhone 6/6s. We are really liking these new headphones! Check out these great “**Spring Fever deals**”:http://www.smalldog.com/springfever/spring-fever and more.

  • _Hello Friends_,

    It is hard to believe that it is February already. There is almost no snow up in Vermont and Artie is reporting that farmers are already gathering sap from the maple trees to make syrup. The Iowa caucuses have come and gone and on Tuesday the first in the nation primary is next door in New Hampshire. Being a leap year my granddaughter, Gracie, will have her 4th real birthday on the 29th. She was recently chosen as guest composer on Vermont Public Radio. You can hear her interview and one of her “**compositions**”:http://digital.vpr.net/post/student-composer-showcase-gracie-bangoura#stream/0 online. 

    February is also Black History month and each week in Kibbles and on our “**blog**”:http://blog.smalldog.com we will be honoring Black History. It is fun researching and writing these little bios of Black American heroes and heroines.  

    Florida’s governor declared a state of emergency in four counties regarding the horrible tragedy unfolding in Brazil with the Zika virus. One thing that is not being widely reported is the apparent link to genetically modified mosquitos and the microcephaly disaster. Apparently, Brazil was the site of a massive experiment with genetically modified mosquitos that were released into the wild. They were proposing a similar release for here in the Florida Keys but it has not happened. The Zika virus has been around since 1947 and this is the first big outbreak of microcephaly. You can “**read more about it,**”:http://www.theecologist.org/News/news_analysis/2987024/pandoras_box_how_gm_mosquitos_could_have_caused_brazils_microcephaly_diasaster.html regardless of whether that analysis is true, I think releasing genetic mosquitos is a bad idea.

    I am happy to announce that Small Dog Electronics will be offering GoPro cameras and accessories in our stores this month. We have had lots of requests for these action cameras from our customers and we finally have secured the line for our stores. We will talk more about GoPro as we get them into stock.  

    This week’s Kibbles & Bytes special is a “**Hammerhead charging bundle**”:http://www.smalldog.com/wag900002149/special-save-20-on-hammerhead-charging-bundle As you know we manufacture rugged braided lightning cables that are certified by Apple with their MFI “Made for iPhone” designation. This means that our manufacturer has passed all the tests with Apple and use genuine Apple lightning connectors. You do not have to worry about compatibility with MFI designation. This bundle includes two of these braided cables, our Hammerhead 2-port home charger and Hammerhead 2-port car charger. Each of these chargers have the capacity to charge an iPhone and an iPad simultaneously. Sold separately, this bundle would be $72.96 but exclusively for Kibbles & Bytes readers this week you can have this handy bundle for only “**$49.99!**”:http://www.smalldog.com/wag900002149/special-save-20-on-hammerhead-charging-bundle 

  • 20 Years of Service.

    !http://blog.smalldog.com/images/4613.jpg!

    Small Dog Electronics has been your local Apple Specialist for 20 years! Not only do we sell the latest Apple products and have some of the most knowledgeable staff around, we offer some of the best *one on one training* and *consulting* services around. Should Santa put something under the tree this year that your just not sure about how you can use it, do not worry, we have got your back and it doesn’t matter where the product came from. Stop into any of our retail stores or give us a call and we will get you getting the most out of your Apple products.

    “!http://blog.smalldog.com/images/4612.jpg!”:http://www.smalldog.com/macthehalls

    Not only do we have great services to help you get the most out of your Apple product, but we have some great deals going on in all of our retail stores *December 9th through the 15th*! Visit any of our retail stores in Rutland, Waitsfield or South Burlington or visit “www.smalldog.com/macthehalls”:http://www.smalldog.com/macthehalls for these deals or more information about what Small Dog services might benefit you.