Hacker News new | ask | show | jobs
by raesene6 3483 days ago
I've done many password audits over the years and all monthly password changes does it make people use sequence passwords (e.g. MyPass1!, MyPass2!, MyPass3!) which are easily guessed by the attacker once they have one instance of the sequence, so really monthly changes add very little in exchange for the hassle they introduce.

The more sensible approach is not to force periodic change and only change where there is a suspicion of breach.