Changing Passwords Periodically Doesn’t Increase Security

Does your organization or some financial website require you to create a new password periodically? This practice was recommended long ago, but some organizations haven’t kept up with current recommendations that discourage such policies. If you’re bound by a password expiration policy, you can use this article to encourage your IT department or financial institution to update its approach to password security.

The rationale behind password expiration policies was that if an attacker were to steal a password database and decrypt some passwords, they would work for only a limited period, lessening the risk of unauthorized access. Even if an attacker gained access to an account, they could remain undetected only if they didn’t change the password, and that access wouldn’t last indefinitely.

Over time, security experts realized that the problem wasn’t so much how long an attacker could remain undetected but allowing users to set weak passwords that could be decrypted. It turns out that users often choose weaker passwords when they know they will have to change them, perhaps by tweaking a previous password for easier memorization. This fact hasn’t been lost on attackers, making it easier for them to figure out future passwords. In other words, attempting to increase security by requiring users to change passwords paradoxically reduces security.

The National Institute for Standards and Technology (NIST) is a US government agency that develops cybersecurity standards and best practices for the federal government that large corporations and other institutions tend to follow. In 2017, NIST changed its guidelines to say, “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).” In a FAQ, NIST explains:

Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets have been compromised since attackers can apply these same common transformations.

Of course, if there’s evidence of unauthorized access or a breach of the password database, all passwords should be invalidated and everyone should be required to create a new password immediately—that’s entirely different than requiring passwords to be changed on a schedule.

Interestingly, NIST also doesn’t recommend password composition requirements—such as requiring the password to contain a letter, number, and special character—because users tend to devise predictable techniques to meet such requirements, such as appending an exclamation point to every password. Instead, NIST encourages longer passwords because a long password that’s easily remembered and typed can be stronger than a shorter password composed of random characters. Password managers can generally create both types.

If you’re forced to change a website password periodically, it’s easiest to use a password manager to generate and enter a new strong password, and you won’t have to memorize the new password. For the very few passwords you must remember and type manually, aim for longer passwords that won’t trip up your fingers while typing or require numerous switches of iPhone uppercase and numeric keyboards. To aid memorization, perhaps consider choosing words for your password from categories with many possibilities. For instance, if your initial password is gouda-purple-1989-New-York, the next one could be cheddar-black-2011-Des-Moines. Both are strong in their own right, but only you would know the categories used for each portion.

(Featured image based on an original by iStock.com/designer491)


Social Media: Security experts no longer recommend password expiration policies that require users to change their passwords periodically. Here’s why.

Similar Posts

  • B.B. King – The King of the Blues

    For more than half a century, Riley B. King – better known as B.B. King – defined the blues for a worldwide audience. Since he started recording in the 1940s, he has released over fifty albums, many of them classics. He was born September 16, 1925, on a plantation in Itta Bena, Mississippi, near Indianola. In his youth, he played on street corners for dimes, and would sometimes play in as many as four towns a night. In 1947, he hitchhiked to Memphis, TN to pursue his music career. Memphis was where every important musician of The South gravitated, and it supported a large musical community where every style of African American music could be found. B.B. stayed with his cousin Bukka White, one of the most celebrated blues performers of his time, who schooled B.B. further in the art of the blues.

    B.B.’s first big break came in 1948 when he performed on Sonny Boy Williamson’s radio program on KWEM out of West Memphis. This led to steady engagements at the Sixteenth Avenue Grill in West Memphis, and later to a ten-minute spot on black-staffed and managed Memphis radio station WDIA. “King’s Spot,” became so popular, it was expanded and became the “Sepia Swing Club.” Soon B.B. needed a catchy radio name. What started out as Beale Street Blues Boy was shortened to Blues Boy King, and eventually B.B. King.

    In the mid-1950s, while B.B. was performing at a dance in Twist, Arkansas, a few fans became unruly. Two men got into a fight and knocked over a kerosene stove, setting fire to the hall. B.B. raced outdoors to safety with everyone else, then realized that he left his beloved $30 acoustic guitar inside, so he rushed back inside the burning building to retrieve it, narrowly escaping death. When he later found out that the fight had been over a woman named Lucille, he decided to give the name to his guitar to remind him never to do a crazy thing like fight over a woman. Ever since, each one of B.B.’s trademark Gibson guitars has been called Lucille.

    B.B. was inducted into the Blues Foundation Hall of Fame in 1984 and into the Rock and Roll Hall of Fame in 1987. He received NARAS’ Lifetime Achievement Grammy Award in 1987, and has received honorary doctorates from Tougaloo(MS) College in 1973; Yale University in 1977; Berklee College of Music in 1982; Rhodes College of Memphis in 1990; Mississippi Valley State University in 2002 and Brown University in 2007. In 1992, he received the National Award of Distinction from the University of Mississippi.

    B.B. King came to Vermont many times and I had the pleasure of being at several of his concerts. He died last year at the age of 90 and was performing to sold out crowds right up until he died. B.B. King is gone but the –The Thrill is Gone- lives forever.

  • Backups: Trust but Verify

    It’s easy to assume your backup app—whether it’s Time Machine, Carbon Copy Cloner, Backblaze, Retrospect, or something else—is quietly doing its job. But…