This practice is not recommended anymore, yet still found in many enterprises.

  • RecluseRamble@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    3 months ago

    Never is too long.

    Why? Frequent password changes have been shown to result in weaker passwords. What’s wrong with keeping a strong one indefinitely? I mean an actual strong one not one character more than what’s currently bruteforceable.

    • CompN12@lemmy.frozeninferno.xyz
      link
      fedilink
      arrow-up
      2
      arrow-down
      3
      ·
      3 months ago

      Forever is vulnerable to phishing attacks, same reason why monthly is getting discouraged. Monthly is weaker because the average person does slight variation, which attackers LOVE.

      • RecluseRamble@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        1
        ·
        3 months ago

        Frequent password changes don’t protect against phishing.

        And while a high frequency like monthly changes will probably result in even weaker passwords, also yearly changes will make people choose weak passwords.