Forced rotation can create predictable passwords

Being made to change your password every ninety days was standard advice for decades, and it has been withdrawn, because it made things worse.

People do not invent a fresh strong password four times a year. They increment the one they had. Spring2026 becomes Summer2026. That is entirely predictable, and it means an attacker who learns one password can often guess the next. Current guidance is to change a password when there is a reason to, such as a breach or a suspicion, and otherwise leave a long, unique password alone.

More on Passwords and secrets