Educause Security Discussion mailing list archives

Re: Frequency of password change


From: Brian Wheeler <BWheeler () UWYO EDU>
Date: Mon, 22 Aug 2005 15:35:10 -0600

http://www.schneier.com/blog/archives/2005/06/write_down_your.html


http://news.com.com/Microsoft+security+guru+Jot+down+your+passwords/2100
-7355_3-5716590.html


Gene,

        Here are two links that may help.

                Thanks,

                        Brian



-----Original Message-----
From: Gene Spafford [mailto:spaf () CERIAS PURDUE EDU] 
Sent: Monday, August 22, 2005 2:49 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Frequency of password change

I know this has been a topic here before, but I failed to archive the  
info.  Does anyone have references to any good studies that show that  
changing passwords once a month (or every 8 weeks, etc) is too  
FREQUENT and leads to more cases of people forgetting passwords,  
picking trivial passwords, writing them down, etc.

Thanks,

Current thread: