It's a question we encounter all the time: Should we change the passwords we use frequently?
You would normally expect the FBI to provide effective security advice, but a recent tweet has many security experts wondering if that's the case.
Specifically, the FBI on November 25th sent out an advisory tweet to (supposedly) help internet users stay safe.
“Shopping online this holiday season? Keep your accounts secure, use strong passwords, and change them frequently,” the FBI says.
Shopping online this holiday season? Keep your accounts secure, use strong passwords & change them frequently. #cyber #blackfriday pic.twitter.com/56a9VmIqxv
— FBI (@FBI) November 25, 2016
Securing accounts with strong passwords is indeed good advice, but the last part of the suggestion has caused controversy. Changing passwords frequently is often described as a bad practice, because doing so repeatedly can eventually lead to using easy passwords that can be quickly cracked by hackers.
Furthermore, it is proven that companies that force their employees to constantly change their passwords are more exposed to attacks for the same reasons: employees end up using simpler passwords that are easier to remember, which is not the most secure practice.
So security experts questioned the FBI's tweets, and one of those who recommended exactly the opposite was Per Thorsheim.
In a statement to Motherboard, Thorsheim explained that frequently changing passwords should not be done and that there are other ways to stay safe online.
“I am surprised and saddened to see that the FBI continues to give such advice when credible academic research, numerous organizations, companies, and the US government itself have been reporting for at least half a year now that frequently changing passwords is a bad idea.”
“While I don’t know who at the FBI is in control of their Twitter account, it seems they are unaware of current best practices.”
So, how can you protect yourself online without changing passwords frequently?
The easiest way is to use a password manager that can generate and “remember” complex passwords that are hard to crack. Of course there are many password managers, such as LastPass, 1Password, RoboForm, etc., but they store the passwords in the cloud.
Our tip: Use an offline password manager like KeePass. It's free and stores your passwords locally using strong encryption.
Additionally, be sure to enable two-factor authentication on any service that has the security feature and avoid using the same passwords across multiple services.
