Changing Passwords Periodically Doesn’t Increase Security

Does your organization or some financial website require you to create a new password periodically? This practice was recommended long ago, but some organizations haven’t kept up with current recommendations that discourage such policies. If you’re bound by a password expiration policy, you can use this article to encourage your IT department or financial institution to update its approach to password security.

The rationale behind password expiration policies was that if an attacker were to steal a password database and decrypt some passwords, they would work for only a limited period, lessening the risk of unauthorized access. Even if an attacker gained access to an account, they could remain undetected only if they didn’t change the password, and that access wouldn’t last indefinitely.

Over time, security experts realized that the problem wasn’t so much how long an attacker could remain undetected but allowing users to set weak passwords that could be decrypted. It turns out that users often choose weaker passwords when they know they will have to change them, perhaps by tweaking a previous password for easier memorization. This fact hasn’t been lost on attackers, making it easier for them to figure out future passwords. In other words, attempting to increase security by requiring users to change passwords paradoxically reduces security.

The National Institute for Standards and Technology (NIST) is a US government agency that develops cybersecurity standards and best practices for the federal government that large corporations and other institutions tend to follow. In 2017, NIST changed its guidelines to say, “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).” In a FAQ, NIST explains:

Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets have been compromised since attackers can apply these same common transformations.

Of course, if there’s evidence of unauthorized access or a breach of the password database, all passwords should be invalidated and everyone should be required to create a new password immediately—that’s entirely different than requiring passwords to be changed on a schedule.

Interestingly, NIST also doesn’t recommend password composition requirements—such as requiring the password to contain a letter, number, and special character—because users tend to devise predictable techniques to meet such requirements, such as appending an exclamation point to every password. Instead, NIST encourages longer passwords because a long password that’s easily remembered and typed can be stronger than a shorter password composed of random characters. Password managers can generally create both types.

If you’re forced to change a website password periodically, it’s easiest to use a password manager to generate and enter a new strong password, and you won’t have to memorize the new password. For the very few passwords you must remember and type manually, aim for longer passwords that won’t trip up your fingers while typing or require numerous switches of iPhone uppercase and numeric keyboards. To aid memorization, perhaps consider choosing words for your password from categories with many possibilities. For instance, if your initial password is gouda-purple-1989-New-York, the next one could be cheddar-black-2011-Des-Moines. Both are strong in their own right, but only you would know the categories used for each portion.

(Featured image based on an original by iStock.com/designer491)


Social Media: Security experts no longer recommend password expiration policies that require users to change their passwords periodically. Here’s why.

Similar Posts

  • New Apple Creator Studio Bundles Pro Apps

    Apple has introduced Apple Creator Studio, a subscription bundle of Final Cut Pro, Logic Pro, Pixelmator Pro, Motion, Compressor, and MainStage, priced at…

  • _Hello Friends,_

    The big winter storm called Jonas is heading for the east coast and Vermonters are hoping that it tracks north of the current projections but it looks like it might miss northern New England and hit the coastal areas. The lack of snow in Vermont and the unusually high temperatures have hit the Vermont ski areas and local merchants pretty hard. Here it is the end of January and no significant snow in Vermont. Well for all the skiers and especially for the businesses I hope that those areas that can’t really handle snow get bypassed and Vermont gets the big dump because Vermonters are ready.

    Down here in Key West it has been sort of cool meaning I have to wear long pants and shoes, although if it was this warm in Vermont everyone would be in shorts. Down here when it gets below 65 you see people with down coats. NOAA reported this week that 2015 was the warmest year in recorded history breaking the record from 2014 by far.

    Apple honored Dr. Martin Luther King, Jr. on its home page on the national holiday on Monday with Dr. King’s quotation “Life’s most persistent and urgent questions is, What are you doing for others”. Tim Cook tweeted his respects, too. I had the honor of marching with Dr. King and share this respect, he was truly one of the great Americans of all time

    We always advertise our “Celebrate Diversity” slogan during this time of the year. We strongly feel that you gain strength through diversity whether it is race, religion, national origin or sexual orientation. I remember a long time ago we had a series of Celebrate Diversity web banners that created a lot of controversy with some sites refusing to run them. Diversity is much more mainstream now despite some candidates for President attempting to divide us.

    This week’s Kibbles & Bytes Exclusive is weather related with $20 off the “**Tempus Pro Bluetooth Weather Stations.**”:http://www.smalldog.com/wag900002127/special-save-20-on-tempus-pro-bluetooth-weather-station This was one of the most popular gifts this holiday season and is a great way to keep track of the weather in your microclimate. This complete weather station includes indoor and outdoor sensors that measure temperature, humidity, rainfall, wind and barometric pressure. Complete with mounting hardware it is simple to install and once you download the App you can monitor the weather on your iPhone or iPad. Read a Small Dogger review of the Tempus Pro “**here.**”:http://blog.smalldog.com/article/fody-weather-station/ Normally, $159.99 this week Kibbles & Bytes readers can get the Tempus Pro Weather Station for only **$139.99**