Skip to main content

Want some security advice? Don’t reset your passwords too often

keeper most common passwords 2016 worst 2015
Image used with permission by copyright holder
Setting your password as “password” has long been dinged as a sure-fire way to invite trouble when it comes to your digital privacy. And obviously, if you’re using the same password for everything on the Internet, you may be in trouble. But while security firms have long discussed the common pitfalls of online security, another practice that may seem solid in theory is now being warned against as well. On Thursday, in observance of World Password Day, the U.K. government urged its citizens not to change their passwords too frequently, claiming that this practice is actually more harmful than it is helpful.

“In 2015, we explicitly advised against it [changing passwords],” British intelligence and security organization GCHQ’s Communications-Electronics Security Group (CESG) wrote recently. “This article explains why we made this (for many) unexpected recommendation, and why we think it’s the right way forward.”

So what’s the issue with constantly changing things up? According to the organization’s 16-page report, repeatedly resetting your codes “doesn’t take into account the inconvenience to users.” A secure password, CESG notes, should be both long and random, which makes them fundamentally difficult to remember. And while you can create and remember a few long and random strings, it’s hard to do this for dozens of passwords. “When forced to change [a password], the chances are that the new password will be similar to the old one,” security experts warn. “Attackers can exploit this weakness.”

CESG also notes that frequent change can be rather counterproductive — in order to remember new strings, users may end up writing them down or storing them in other unsafe ways. There’s also the stronger possibility of forgetting the new password and being locked out of an account, forcing users to find a new password yet again.

“It’s one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack,” CESG concludes. “What appeared to be a perfectly sensible, long-established piece of advice doesn’t, it turns out, stand up to a rigorous, whole-system analysis.”

Editors' Recommendations

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
This game lets hackers attack your PC, and you don’t even need to play it
Genshin Impact characters.

Hackers have been abusing the anti-cheat system in a massively popular game, and you don't even need to have it installed on your computer to be affected.

The game in question is called Genshin Impact, and according to a new report, hackers are able to utilize the game's anti-cheat measures in order to disable antivirus programs on the target machine. From there, they're free to conduct ransomware attacks and take control of the device.

Read more
I tried Stage Manager on my Mac, and now I don’t want to go back
Stage manager in macOS Ventura.

Of all the new MacOS Ventura features announced at Apple’s Worldwide Developers Conference (WWDC), one of the most intriguing was Stage Manager. I’ve been playing around with it since the show, and it feels like it could change the way I work on my Mac for good.

First, a quick explainer. Stage Manager is basically a window management tool. With it activated, your open windows appear on the left of your Mac’s display, and you can click to quickly switch between them.

Read more
I uninstalled Windows on my gaming PC, and I don’t want to go back
A laptop running Linux with a controller sitting on it.

Like many people I've had some recent trouble with Windows. I deal with it because I have to, despite my issues with Windows 11 and its requirements and Microsoft's consistent encroaching on users' privacy. Finally, I decided to do something about it.

I uninstalled Windows 11 on my gaming PC and tried my hand at Linux gaming. The Steam Deck has bolstered Linux support massively in the last few months, and now that I've spent some time with Tux, I don't want to go back.
Why Linux?

Read more