"forced password changes make you safer"
loresecurityIT support
Mandatory 90-day rotations trained people into Password1, Password2 - predictable mutations attackers model. Current guidance: long unique passphrases, changed on evidence of compromise.
NIST SP 800-63B recommends against periodic forced changes and against composition rules; length and uniqueness (via a manager) beat ritual complexity.
Disputed / commonly mistold A popular version of this story is inaccurate - see the note above.
Sources
- NIST SP 800-63B - Digital Identity Guidelines, section 5.1.1.2
- UK NCSC password guidance - the problems with forcing regular expiry