Readers like you keep news free for everyone.

More than 5,000 readers have already pitched in to keep free access to The Journal.

For the price of one cup of coffee each week you can help keep paywalls away.

Support us today
Not now
Dublin: 16°C Wednesday 17 August 2022

You know the advice about changing passwords often? You're likely doing it wrong

We’re not exactly great at coming up with new and original passwords.

Image: Shutterstock/Skylines

WHEN IT COMES to password security, you’re sometimes told to change your password regularly so your account is safe from anyone who tries to access it.

The logic is as follows. If you’re changing it regularly, then it’s harder to guess what your password is and therefore harder to access your account.

It turns out it’s a flawed idea according to one security expert, the US Federal Trade Commission’s chief technologist Lorrie Cranor, who confirmed it at a security conference in Las Vegas recently.

The problem with this advice is it assumes you’ll change your password completely. Most people won’t go to that effort. Instead, they’ll just change a character in their old password.

They might replace a small character with a capital letter, or just add an extra letter or number to the end. Instead of a new password, they are using a slightly modified version of an old password.

“The UNC (University of North Carolina) researchers said if people have to change their passwords every 90 days, they tend to use a pattern and they do what we call a transformation,” Cranor said at the event. “They take their old passwords, they change it in some small way and they come up with a new password.”

The research she’s referring to a UNC study from 2010 which looked at 10,000 expired accounts from employees or students who were required to change their passwords every three months (they obtained the cryptographic hashes which protect these accounts).

The data included the last password used and passwords that changed over time. One of the most common patterns they found was how how often people would just change or add a character to their existing password.

Making a difference

A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article.

Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

For the price of one cup of coffee each week you can make sure we can keep reliable, meaningful news open to everyone regardless of their ability to pay.

These slight changes are what hackers and other bad actors rely on as they’re easy to guess. Developing a program which automatically guesses the most common passwords is usually one way for someone to gain access to accounts.

That’s not to say you shouldn’t change your password ever, but the aim is to make it long and random. Also, if you’re reusing the same one for different sites – which is a terrible idea – you should change that immediately. Using a password manager to help remember complex passwords is one of the best ways of solving this.

Read: Another major security flaw has been discovered on Android phones >

Read: Want to try out new phone features before anyone else? Sign up for beta testing >

About the author:

Quinton O'Reilly

Read next: