How often do you change your password? Surely some of them are old. In fact, most of us only change our passwords when something forces us to do so.
Typically, this can happen if we forget it, or if the service we use requires us to create a new password. Of course, there are also services that require new passwords every few months.
Which approach is right? Using the same password for years, or changing it frequently? Below we will look at the advantages and disadvantages of changing your password frequently:
It makes your account a little more secure
The theory that is generally circulated is that changing your password frequently makes your account more secure.
The argument of course applies if you are the intended victim of a leak, and changing your password frequently will prevent a hacker from continuing to use your account…
Does the argument seem right to you? Maybe so, but it is not as clear-cut as one might expect. A single hacker breaking into your account is enough to cause a lot of damage. So changing your passwords frequently only ensures that you don't share your account with an attacker.
On the other hand, even if your new passwords are stronger than your previous ones, the practice has little benefit.
In a paper from Carleton University (PDF), researchers report that attackers with access to a list of passwords can launch attacks by trying a huge number of passwords in a very short period of time. Low- and medium-strength passwords are at risk.
The paper mathematically proves that even frequent changes to strong passwords failed to prevent attacks, and that the benefit is almost certainly not worth the inconvenience it causes users.
The same paper recommends that system administrators use slow hashing functions such as bcrypt. End users won’t be bothered, and the process makes it harder for attackers to quickly guess a large number of passwords.
Your new password is likely to be insecure
I’m sure we don’t need to tell you how to create a strong password, but some information is worth repeating:
Your password should use a combination of letters, numbers, and symbols (special characters).
It should use some uppercase and some lowercase letters.
It should be longer than 12 characters.
Following the above requirements creates passwords that are strong, but they are difficult to remember.
But let’s look at the scientific data. In 2010, researchers at the University of North Carolina published a paper titled “The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis.” In it, they studied the password histories of old accounts at the university.
The study looked at more than 10,000 old accounts and 51,141 passwords. The researchers performed an offline hash attack and were ultimately able to reveal 60% of the passwords.
Password Managers Local or in the Cloud?
They then used this dataset to see if they could see other passwords associated with the account. The results were surprising. In 17 percent of cases, the next password used for the same account could be found in less than five seconds.
Why? The study concluded that people tend to make very small changes when changing a password frequently. For example, iguru123 could become 1guru123, and newsiguru! could become igurunews!!, and so on.
When should you change your password?
If you suspect that someone is accessing your account without your authorization, you should change your password. If you think that someone was watching you when you entered your online banking credentials, you should change your password again. If you had to “give away” your password somewhere, you should of course change it.
And if you think that you are the victim of a phishing scam, you should change your password.
In all cases, you should make sure that your new password has nothing to do with your old one. Do not use the same main word, and do not put the same special characters in the same places. Of course, do not try to write your old password backwards.
Remember, you should also change your password on all other accounts that use similar passwords. For example, if your Facebook password is iguru1 and your Twitter password is 1iguru, you should change both.
But what about forced password resets?
Is it a good idea for an application or service to force end users to create new passwords? Probably not.
In 2009, the National Institute of Standards and Technology said that regular password changes were “beneficial in reducing the impact of some password compromises,” but were “ineffective in other cases.” Like an oracle from Pythia. Naturally, users get frustrated with having to change passwords every three or so years. forced change.
All of the above arguments may sound complicated. Let’s break it down a bit:
Frequent password changes may make users marginally more secure, but only if the new password is extremely strong.
Forced (frequent) password changes often have a negative effect, as users often choose weaker passwords, or a variation of the old passwords.
