Changing Passwords Periodically Doesn’t Increase Security

Does your organization or some financial website require you to create a new password periodically? This practice was recommended long ago, but some organizations haven’t kept up with current recommendations that discourage such policies. If you’re bound by a password expiration policy, you can use this article to encourage your IT department or financial institution to update its approach to password security.

The rationale behind password expiration policies was that if an attacker were to steal a password database and decrypt some passwords, they would work for only a limited period, lessening the risk of unauthorized access. Even if an attacker gained access to an account, they could remain undetected only if they didn’t change the password, and that access wouldn’t last indefinitely.

Over time, security experts realized that the problem wasn’t so much how long an attacker could remain undetected but allowing users to set weak passwords that could be decrypted. It turns out that users often choose weaker passwords when they know they will have to change them, perhaps by tweaking a previous password for easier memorization. This fact hasn’t been lost on attackers, making it easier for them to figure out future passwords. In other words, attempting to increase security by requiring users to change passwords paradoxically reduces security.

The National Institute for Standards and Technology (NIST) is a US government agency that develops cybersecurity standards and best practices for the federal government that large corporations and other institutions tend to follow. In 2017, NIST changed its guidelines to say, “Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically).” In a FAQ, NIST explains:

Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets have been compromised since attackers can apply these same common transformations.

Of course, if there’s evidence of unauthorized access or a breach of the password database, all passwords should be invalidated and everyone should be required to create a new password immediately—that’s entirely different than requiring passwords to be changed on a schedule.

Interestingly, NIST also doesn’t recommend password composition requirements—such as requiring the password to contain a letter, number, and special character—because users tend to devise predictable techniques to meet such requirements, such as appending an exclamation point to every password. Instead, NIST encourages longer passwords because a long password that’s easily remembered and typed can be stronger than a shorter password composed of random characters. Password managers can generally create both types.

If you’re forced to change a website password periodically, it’s easiest to use a password manager to generate and enter a new strong password, and you won’t have to memorize the new password. For the very few passwords you must remember and type manually, aim for longer passwords that won’t trip up your fingers while typing or require numerous switches of iPhone uppercase and numeric keyboards. To aid memorization, perhaps consider choosing words for your password from categories with many possibilities. For instance, if your initial password is gouda-purple-1989-New-York, the next one could be cheddar-black-2011-Des-Moines. Both are strong in their own right, but only you would know the categories used for each portion.

(Featured image based on an original by iStock.com/designer491)


Social Media: Security experts no longer recommend password expiration policies that require users to change their passwords periodically. Here’s why.

More Insights

Tech Tip

Control Song Transitions in Apple Music

A new feature for Apple Music subscribers in the Music app in iOS 26, iPadOS 26, and macOS 26 is AutoMix, which Apple says causes songs to “transition at the perfect moment, based on analysis of the key and tempo of the music.” It fades between songs as a DJ would, but it’s not always […]

Read More »
Tech Article

Five Invisible Characters That Still Matter in Word Processing and Layout

In earlier eras of word processing, users were much more likely to encounter explanations of document structure—not because everyone had to become an expert, but because knowledge was shared differently. Software shipped with detailed manuals, user groups and training classes focused on how documents worked under the hood, and power users routinely shared mental models […]

Read More »
Tech Tip

Try macOS 26.2’s Edge Light for Low-Light Video Calls

We can’t always guarantee optimal lighting for video calls, especially when using laptops on the go. A new feature in macOS 26.2 Tahoe called Edge Light might help. It’s a video effect that uses the outermost pixels of your Mac’s display to create a bright white rectangle that illuminates your face during video calls. It […]

Read More »
Tech Article

How to Ensure You Don’t Miss Reminders

Recording a task in Apple’s Reminders app on your Mac, iPhone, or iPad is just the first step—the app captures what you need to do—but what matters more is being reminded to take action at the right moment. (The most important step, of course, is following through, but that’s on you.) Here’s how to configure […]

Read More »
Tech Tip

When Google Points to a Chatbot Conversation, Be Skeptical

Here’s something new to watch out for: poisoned chatbot conversations surfaced in Google searches. The sharing features in ChatGPT, Claude, Gemini, Grok, and other chatbots allow users to publish their conversations as public Web pages, which can be indexed by search engines and appear alongside traditional websites in search results. Attackers can seed those conversations […]

Read More »
Tech Article

How to Encourage Successful AI Use in Your Organization

The AI hype train continues to gain momentum, with breathless reports of rapid user growth, billion-dollar deals, and sky-high company valuations. At the same time, it’s easy to highlight AI pilot failures, problematic uses, and worries about job losses. As always, reality lies between the extremes. AI is just another technological tool, like spreadsheets, email, […]

Read More »

If you are here and not sure how to proceed, please call us at 626-286-2350, and we would be happy to help you find a solution to your needs.