CHANGING your passwords regularly can be a bad idea.
That’s according to leading security experts, who say the “password rotating” habit could be causing more harm than good.
It is a common belief that it is important to regularly change your passwords to avoid hacker attacks.
But security experts say updating your passwords on a iPhone or Android every three months has some big disadvantages.
“No, you don’t need to change your password every 90 days,” said Ashley D’Andrea of Keeper Security.
“This idea of regularly changing your password is known as password rotation.
“The main benefit of changing your passwords so frequently is to prevent unauthorized users from accessing private information.”
Sometimes it is necessary to change your password.
For example, if you received an alert that an account has been compromised, it’s important to update your login as soon as possible.
But when you put the pressure on yourself to change all your passwords every 90 days, you’re bound to run into problems.
WHAT’S WRONG WITH CHANGING PASSWORDS?
“For personal accounts, changing your passwords every 90 days could end up being worse than keeping them the same,” warned Ashley.
“Setting up multi-factor authentication (MFA) is a better alternative than changing your passwords every 90 days.
“Because frequent changes can lead you to start using weaker passwords or reusing old passwords. Enabling MFA gives your accounts an additional layer of security.”
For example, Ashley warned that people who change their passwords regularly tend to have easy, memorable logins.
Typically, this means adding something memorable, like a pet’s name, your favorite food, or a local street.
STRONG PASSWORD TIPS – DON’T IGNORE THEM!

Here’s what you should try…
- Use a mixture: Combine uppercase letters, lowercase letters, numbers and special characters.
- Avoid common words: Avoid easily guessable words and phrases.
- Length is important: Look for passwords with at least 12 characters.
- Unique passwords: Use different passwords for different accounts to increase security.
- Passwords: Consider using a series of random words or a memorable phrase.
- Memory Tricks: Use mnemonics or acronyms to remember complex passwords.
- Password managers: Use password management tools to store and generate strong passwords.
This makes it much easier to compromise these passwords.
Likewise, feeling like you need to remember new passwords leads people to reuse logins.
This is a big problem because it means that the compromise of a single account triggers a chain reaction – where other logins that share the same password are also hacked.
Even similar passwords (like changing the number at the end) can be compromised this way.
Additionally, if you constantly change logins (and don’t use a password manager), you run the risk of forgetting your passwords completely.
This can be a huge inconvenience, especially if you are in a hurry.
And the biggest disadvantage of all: the time it takes.
If you have dozens of accounts, it is very difficult to change all of your passwords.
SIGNS THAT YOUR ANDROID PHONE IS INFECTED
Here’s Google’s official list of signs you might have malware on your Android phone…
You may have malware on your device if:
- Google has logged you out from your Google Account to help protect you from malware on your device.
- You notice suspicious signs on your device, such as pop-up ads that don’t go away.
Device symptoms
- Alerts about a virus or infected device
- The antivirus software you use no longer works or no longer works
- A significant decrease in your device’s operating speed
- A significant and unexpected decrease in your device’s storage space
- Your device stops working properly or stops working completely
Browser symptoms
- Alerts about a virus or infected device
- Pop-up ads and new tabs that don’t disappear
- Unwanted Chrome Extensions or Toolbars Keep Coming Back
- Your browsing seems out of your control and redirects to unknown pages or ads
- Your Chrome homepage or search engine keeps changing without your permission
Other symptoms
- Your contacts received your emails or social media messages, but you didn’t send them.
And if it’s not bringing big benefits then you are just wasting time.
However, security experts have admitted that companies (not ordinary people) should practice password rotation.
This is because big companies can set the process to happen automatically – and can impose strict rules on the types of passwords you choose.
So don’t panic if your job requires you to change your password regularly: it’s a good idea.
This story originally appeared on The-sun.com read the full story