Why? Frequent password changes have been shown to result in weaker passwords. What’s wrong with keeping a strong one indefinitely? I mean an actual strong one not one character more than what’s currently bruteforceable.
Forever is vulnerable to phishing attacks, same reason why monthly is getting discouraged. Monthly is weaker because the average person does slight variation, which attackers LOVE.
Frequent password changes don’t protect against phishing.
And while a high frequency like monthly changes will probably result in even weaker passwords, also yearly changes will make people choose weak passwords.
Agreed. My last job, we were forced to change all service account passwords annually but our personal passwords every month or two.
My current job has more domains and systems so I have so many more passwords with varying complexity and age requirements. I just set a calendar event for every four weeks (one expires just under 5 weeks) and change them all to the same generated password that meets all the common requirements and I save it in my password manager.
So every four weeks, it’s seriously this hour+ long ritual for virtually no enhanced security reason.
Never is too long. Monthly is way to short. I like the idea of doing it yearly in conjunction with other it security awareness and training campaigns.
Why? Frequent password changes have been shown to result in weaker passwords. What’s wrong with keeping a strong one indefinitely? I mean an actual strong one not one character more than what’s currently bruteforceable.
Forever is vulnerable to phishing attacks, same reason why monthly is getting discouraged. Monthly is weaker because the average person does slight variation, which attackers LOVE.
Frequent password changes don’t protect against phishing.
And while a high frequency like monthly changes will probably result in even weaker passwords, also yearly changes will make people choose weak passwords.
Agreed. My last job, we were forced to change all service account passwords annually but our personal passwords every month or two.
My current job has more domains and systems so I have so many more passwords with varying complexity and age requirements. I just set a calendar event for every four weeks (one expires just under 5 weeks) and change them all to the same generated password that meets all the common requirements and I save it in my password manager.
So every four weeks, it’s seriously this hour+ long ritual for virtually no enhanced security reason.