Do Strong Web Passwords Accomplish Anything?(schneier.com)
schneier.com
Do Strong Web Passwords Accomplish Anything?
http://www.schneier.com/blog/archives/2009/07/strong_web_pass.html
5 comments
Indeed, this is a very good recall on the old security saying: "If I need your password, I call you and ask you for it."
Yes it makes it easier for users to forget the password. Passwords should be strong enough that brute force attacks aren't easy but some websites try to enforce ridiculously hard password which eventually result in the user forgetting his password. Kinda defeats the purpose.
Assuming that "XX days" === 'less than 100 days', I totally agree.
We use a six month password cycle at work, and I think that's reasonable as it only takes me a few days to remember a password that I use tens of times a day. If it's a password that I use less frequently or a change is mandated more frequently, then I would do the same as Bruce and use something more obvious or only make small changes to the password each time.