How Often Do You Change Your (High Risk, Sensitive) Passwords? No really...

Midpack

Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Joined
Jan 21, 2008
Messages
24,038
Location
NC
I think about it from time to time, but I almost never change most of my passwords, and they are all in my password manager - I have about 80 active passwords - most unique, and probably another 50 that I'll never login again on. I did recently delete accounts on a couple dozen, but I doubt that does any good, they'll keep what the hoovered up in the past. Some are 16 character strong passwords, others are simpler with less characters. I think DW's are all simpler unfortunately...

I change the passwords on my 15 high-risk, sensitive passwords (anything financial, medical or email) every year or two. All of them are 15-16 character 'strong' passwords with 2FA if available. None of them are in my password manager or any hard drive. I type them in manually off a piece of paper, from a spreadsheet on a flash drive. Probably overkill...

After reading this article, I don't feel so bad. Evidently the 'every 3-6 months' recommendation you often read about is outdated. I hope so...
But if you have a really good password for a service or account, you can probably keep it for life (or until there's a breach). Just ensure it's long, strong, and unique to the service.
The story I wrote years ago about passwords that spurred all this included coverage of a survey in which PCMag specifically asked, "How often do you change your passwords?" About 74% of respondents claimed to change their passwords at a minimum of every six months. I don't buy it. The cynic in me thinks people believe they are supposed to change passwords often, and don't want to admit to us (or themselves) that they don't. Perhaps they're annoyed because their workplace or some service forces them into frequent changes.

Stop feeling guilty! The experts told us years ago to quit making regular password changes. It's time we listened. As long as your password is already reasonably strong and unique to every site and service, changing it frequently is not much help to you.

Unless it's compromised in a data breach, of course, then change it immediately.

 
Last edited:
Less accounts less logins if I can wrangle it.
I wish that was in my planning many years ago. I have a hair over 100 online accounts, nearly all of which I *cannot* delete. Many were opened for various interests that have become unnecessary over the years. Home theater, music, computer building and software, gardening, bicycling, sports, autos, shopping, financial, retirement, services, utilities, postal services, email, streaming TV, ... :(
 
I forget those unused accts. No wringing of hands over what I cannot change.
 
I wish that was in my planning many years ago. I have a hair over 100 online accounts, nearly all of which I *cannot* delete. Many were opened for various interests that have become unnecessary over the years. Home theater, music, computer building and software, gardening, bicycling, sports, autos, shopping, financial, retirement, services, utilities, postal services, email, streaming TV, ... :(
I have tons of old, now unused sites, many with the same weak password. I don't worry about them. Any credit card info they may have had is long expired. My address, telephone number and probably SSN is out there on the dark web, so I don't think anyone can use those nefariously even if they were to log in.

My passwords I care about are all long random strings with 2FA and I don't change those unless something specific has happened (reported breach etc.). My LastPass account does the heavy lifting and I do change the master password to that account occasionally. My bigger concern is being phished as detailed in a another thread I started.
 
Never change them. I use an email based on how critical the account is to me. Finance, email, password mgmt and government all get the my main email. Medical is next mainly due to their history of incompetence in preventing breeches. Sites with my credit card is third and everything else is gets my fourth email. Everything but the fourth category get random generated passwords.

I experimented with using passkeys but the sites where I tried it still do go through the whole 2FA so I don’t see the value of this complication over continue to use a password manager.
 
2FA and every 2 months for me. Passwords are as long as allowed and done with a password generator.
 
I rarely if ever change my passwords. I use strong, cryptic passwords (15-25 characters that are a jumble of upper, lower, digits, symbols) that are unique to that account and automatically generated by my password manager software (1Password). I also use cellular 2FA and/or an authenticator app. I don't really have any of my passwords memorized except the password to get into 1Password and my computer login account.
 
I change if required. I use 2FA and as much security stuff as I can for financial accounts.
some I have on paper, secured away, some I have written down and in the safe.
I have a ton of other miscellaneous online acts that are not tied to anything financial, and don't do anything with those.
Probably should change more often. Luckily no breaches recently and none directly with financial stuff.
 
Never change them. I use an email based on how critical the account is to me. Finance, email, password mgmt and government all get the my main email. Medical is next mainly due to their history of incompetence in preventing breeches. Sites with my credit card is third and everything else is gets my fourth email. Everything but the fourth category get random generated passwords.

I experimented with using passkeys but the sites where I tried it still do go through the whole 2FA so I don’t see the value of this complication over continue to use a password manager.
Thought I was the only one who did that. I have three email accounts, one that I use for family and friends, one for organizations I care about, and everyone else gets the third one.
 
Use 2FA on important financial sites as well as using lock down features for any over/under amounts or non scheduled transfers.
 
I pretty much do the same as the OP but most of my 'sensitive' passwords are 32-characters long, letters (upper and lower case), numbers and special characters.
 
Never. Most are 16 to 20 random characters upper and lower case, numbers and special characters and the same for userids if not forced to use an email. Many are 15+ years old. Never had any issues. Answers to security questions are nonsense answers.
 
I’m convinced it won’t be too long before some nefarious entity unleashes AI powerful enough to blow past every security protocol we’ve ever known. At this rate, we’ll be logging into our accounts with a fingerprint, a retina scan, a breathalyzer test, and just for good measure a QR link to our urine sample analysis.
 
I use a YubiKey on every account I can. I think I am secure.
 
While I have some good practices around password management, I have to admit that I’d likely not score better than a C at best. I do keep my passwords on a password protected spreadsheet and I do get help from being forced to use 2FA but I really need to spend some time and get my passwords in better shape. To answer the direct question, I don’t normally change any passwords. I had some weird activity on my email account a couple years ago and I change that password but that was an exception and not the rule.
 
Thank goodness for Dashlane! Even if my face or finger ID doesn’t work to get me in, it’s the ONLY password I need to remember to get me into all of my protected sites!
 
Last edited:
Rarely do we change passwords.

For a long time now the Mac generates some God Awful long convoluted PW and saves it automatically and then auto fills it in.

I will admit that when the internet started my password was my initials123, e.g. abc123.
This served us well for at least 20 year - until we were forced to make them more complicated

I like the finger thing on the Mac and the face ID thing on the iPhone.
 
A couple of years ago I used the tool in my password manager to security check all my passwords and then made the effort to go through and change all my “weak” passwords, and duplicated passwords, and now I never change a password unless I need to.
 
Only once.
I use a password manager, so my passwords are the max allowed, meaning most are 25->30 characters randomly generated.

My longest password is 80 characters.

Incredibly, one bank account until 5 years ago, had a 4 digit pin as the password, then they moved to 6 digits. Finally this year they moved to 20 characters. BUT still use the 6 digit pin for a phone password :facepalm:

Different password for every site.
 
And how is that working for you. I had LastPass until it was compromised twice.
.
 
Back
Top Bottom