Educause Security Discussion mailing list archives

Frequency of password change


From: Gene Spafford <spaf () CERIAS PURDUE EDU>
Date: Mon, 22 Aug 2005 15:49:03 -0500

I know this has been a topic here before, but I failed to archive the
info.  Does anyone have references to any good studies that show that
changing passwords once a month (or every 8 weeks, etc) is too
FREQUENT and leads to more cases of people forgetting passwords,
picking trivial passwords, writing them down, etc.

Thanks,

Current thread: