Forced Password Rotation Is Security Theater

Make people change their password every ninety days and you do not get ninety days of fresh security. You get Summer2024! followed by Autumn2024! followed by a sticky note on the monitor. NIST stopped recommending scheduled rotation years ago, for exactly this reason: it trades a small theoretical gain for a large, measurable decline in password quality.

The evidence is not subtle. Forced rotation pushes people toward predictable patterns, and predictable patterns are the first thing an attacker tries. You have not raised the bar. You have published the rule the bar follows.

Rotate credentials when there is a reason to — a breach, a departure, a suspected leak. Otherwise, spend the policy budget on the things that actually move the needle: long passphrases, a password manager, and multi-factor everywhere. Security you can measure beats security you can perform.

No comments yet — be the first.

Leave a comment

Comments are welcome — disagreement included, in the spirit of free speech. Come in good faith and keep it civil. Cruelty, spam, and bad-faith trolling get moderated out.