Forced rotation can create predictable passwords
Being made to change your password every ninety days was standard advice for decades, and it has been withdrawn, because it made things worse.
People do not invent a fresh strong password four times a year. They increment the one they had. Spring2026 becomes Summer2026. That is entirely predictable, and it means an attacker who learns one password can often guess the next. Current guidance is to change a password when there is a reason to, such as a breach or a suspicion, and otherwise leave a long, unique password alone.
More on Passwords and secrets
- Password length beats decorative complexityAdd wheels, not squiggles
- Salts make identical passwords look differentOne grain each
- Every secret copy creates another secret to protectEvery copy needs its own guard
- Secrets in source control have a long memoryThe deletion is just another commit
- Environment variables are not secret vaultsA label on the outside of the bag
- Temporary credentials shrink the theft windowSame theft, different window
