Changing Passwords Periodically Doesn’t Increase Security

Does your organization or some financial website require you to create a new password periodically? This practice was recommended long ago, but some organizations haven’t kept up with current recommendations that discourage such policies. If you’re bound by a password expiration policy, you can use this article to encourage your IT department or financial institution to update its approach to password security.

The rationale behind password expiration policies was that if an attacker were to steal a password database and decrypt some passwords, they would work for only a limited period, lessening the risk of unauthorized access. Even if an attacker gained access to an account, they could remain undetected only if they didn’t change the password, and that access wouldn’t last indefinitely.

Over time, security experts realized that the problem wasn’t so much how long an attacker could remain undetected but allowing users to set weak passwords that could be decrypted. It turns out that users often choose weaker passwords when they know they will have to change them, perhaps by tweaking a previous password for easier memorization. This fact hasn’t been lost on attackers, making it easier for them to figure out future passwords. In other words, attempting to increase security by requiring users to change passwords paradoxically reduces security.

The National Institute for Standards and Technology (NIST) is a US government agency that develops cybersecurity standards and best practices for the federal government that large corporations and other institutions tend to follow. In 2017, NIST changed its guidelines to say, “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).” In a FAQ, NIST explains:

Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets have been compromised since attackers can apply these same common transformations.

Of course, if there’s evidence of unauthorized access or a breach of the password database, all passwords should be invalidated and everyone should be required to create a new password immediately—that’s entirely different than requiring passwords to be changed on a schedule.

Interestingly, NIST also doesn’t recommend password composition requirements—such as requiring the password to contain a letter, number, and special character—because users tend to devise predictable techniques to meet such requirements, such as appending an exclamation point to every password. Instead, NIST encourages longer passwords because a long password that’s easily remembered and typed can be stronger than a shorter password composed of random characters. Password managers can generally create both types.

If you’re forced to change a website password periodically, it’s easiest to use a password manager to generate and enter a new strong password, and you won’t have to memorize the new password. For the very few passwords you must remember and type manually, aim for longer passwords that won’t trip up your fingers while typing or require numerous switches of iPhone uppercase and numeric keyboards. To aid memorization, perhaps consider choosing words for your password from categories with many possibilities. For instance, if your initial password is gouda-purple-1989-New-York, the next one could be cheddar-black-2011-Des-Moines. Both are strong in their own right, but only you would know the categories used for each portion.

(Featured image based on an original by iStock.com/designer491)


Social Media: Security experts no longer recommend password expiration policies that require users to change their passwords periodically. Here’s why.

Similar Posts

  • _Dear Friends,_

    Don’s making the voyage home this week from Key West back to the Green Mountains. He’s in for a bit of a shock when he gets back. Mother Nature seems to have gotten a bit confused this week. I mentioned in the fall that I was taking a new stance on winter and was going to embrace it this year and I truly did my best though we didn’t see much snow. But when we get a snow in late April, I choose to just ignore it. I didn’t bother to shovel off my deck and I left the hose to water my horses just thrown on the ground. In the end both these decisions only made my life harder. I had to lug water buckets for my horses as my hose was not only frozen to the ground, but frozen itself because I didn’t take the time to drain the water out of it. All the slush and snow I ignored on my deck was a sprained ankle waiting to happen and my screen door only opened halfway once everything froze back up. Well, let’s just hope this was finally the last of it and spring will finally show up for real. It always looks a little funny when the trees are starting to bud and there is still snow on the ground.

    The snow this week was a bit of a shock to many of us, and so was the latest financial report from Apple. For the first time in 13 years, Apple’s financial report showed lower than expected sales figures. iPhone sales showed their first decline since their release and iPad sales have been sluggish for several quarters now, but we’ll have more on this later in Kibbles.

    This week’s Kibbles & Bytes exclusive is perfect for the on-the-run Mom on your list or anyone who is on the go and trying to fit time in for themselves between home and the office. This week only, save $40 on this perfect on-the-run bundle. Get the OutDoor Tech Kodiak mini, the BlueAnt Pump Mini headphones and the Belkin Slim-Fit Plus armband for “**$99.97**.”:http://www.smalldog.com/wag900002212 This bundle is perfect for ensuring the mom who does it all can keep can keep her phone going to capture those special moments or squeeze in an important call during her workout.

  • _Dear Friends,_

    I tuned into the Apple special “Let Us Loop You In” event on my Apple TV. We will talk about the new hardware and software but there were a few things that caught my attention that really help to define Apple as a truly different company.

    The first was Apple’s environmental commitment. They now boast that 90% of their operations, worldwide, are powered by renewable energy and 100% in the USA. This is a unique accomplishment that is made even more remarkable by Apple’s size. While Small Dog Electronics is proud to power our Waitsfield headquarters and S. Burlington store by solar energy, we have not yet reached the point of powering all our operations which is something Apple has done both by purchasing renewable energy and installing large scale solar arrays at their locations both in the USA and China.

    Their environmental commitment goes further with an awareness of the impact their products have on the waste stream. They made a point to describe the materials used which have lower impact and talked about their recycling program, too. The robot, Liam, that disassembles iPhones into its component parts was very cool and is a further demonstration of Apple’s leadership in environmental stewardship.

    The other part of the announcement that caught my eye was the extension of Apple’s altruistic Research Kit tool that has helped researchers gather data on several chronic diseases. CareKit takes that a step further, offering tools that help patients and their medical providers manage those chronic diseases. They already have several new apps in development, including one that provides post-surgical care monitoring and another for diabetes monitoring. Research Kit and CareKit are both open-source software that do not necessarily provide any revenue stream for Apple but provides the tools to improve health. I am very proud of Apple for its initiatives in these areas.

    This week’s Kibbles & Bytes exclusive is a “**home and away USB charger bundle.**”:http://www.smalldog.com/wag900002185/home-and-away-usb-charger-bundle-one-for-the-car-one-for-home This features the Hammerhead 2-port USB Automotive charger and the Hammerhead 2-port wall charger. Both have sufficient power to charge both an iPhone and iPad. If you are like me, you can never have too many chargers and this bundle is a great way to get a spare for you home and car! Normally, this bundle is $34.98 but exclusively for Kibbles & Bytes readers this week, it is $10 off at “**$24.98!**”:http://www.smalldog.com/wag900002185/home-and-away-usb-charger-bundle-one-for-the-car-one-for-home

  • Why Every Business Needs an AI Policy

    Are employees at your company surreptitiously using artificial intelligence tools like ChatGPT, Claude, Copilot, and Gemini for everyday business tasks? It’s likely. An…