Forced Password Rotation Is Security Theater
Make people change their password every ninety days and you do not get ninety days of fresh security. You get Summer2024! followed by Autumn2024! followed by a sticky note on the monitor. NIST stopped recommending scheduled rotation years ago, for exactly this reason: it trades a small theoretical gain for a large, measurable decline in password quality.
The evidence is not subtle. Forced rotation pushes people toward predictable patterns, and predictable patterns are the first thing an attacker tries. You have not raised the bar. You have published the rule the bar follows.
Rotate credentials when there is a reason to — a breach, a departure, a suspected leak. Otherwise, spend the policy budget on the things that actually move the needle: long passphrases, a password manager, and multi-factor everywhere. Security you can measure beats security you can perform.
root@naomislivko:~/articles# cat comments
No comments yet — be the first.