"forced password changes make you safer"

lore

securityIT support

Mandatory 90-day rotations trained people into Password1, Password2 - predictable mutations attackers model. Current guidance: long unique passphrases, changed on evidence of compromise.

NIST SP 800-63B recommends against periodic forced changes and against composition rules; length and uniqueness (via a manager) beat ritual complexity.

Disputed / commonly mistold A popular version of this story is inaccurate - see the note above.

Sources

  • NIST SP 800-63B - Digital Identity Guidelines, section 5.1.1.2
  • UK NCSC password guidance - the problems with forcing regular expiry

All glossary entries