My IT guy told me to stop changing my password every 90 days and I argued with him for 20 minutes
I sat down with our IT guy Dave at the office in Spokane last week and he said the 90 day password reset rule is basically dead. I pushed back hard because I always figured fresh passwords mean fewer breaches. He explained that forcing people to change constantly just makes them pick weak stuff like Summer2024! and tack a number on the end, which is way easier for a crook to guess. Now I am honestly torn and still changing mine monthly out of habit. Has anyone else dropped the 90 day thing at work and actually felt safer?
Does Dave have a magic crystal ball that tells him nobody ever gets hacked on his watch? The thing is, a password that never changes basically gives a crook unlimited time to crack it or steal it from some old breach list, and if your bank or email gets hit you cannot just swap it out before the damage is done. Every security expert on TV says the same thing Dave says, but those are the same folks who told us to use "password123" complexity rules for years and look how that turned out. I get that people write down "Summer2024!" on a sticky note, but at least a fresh password locks the door again after a leak, whereas the old one stays open forever. You keep changing yours monthly, and honestly I would too, because paranoia has kept more people safe than trust ever has.