Why does 90-day rotation with complexity rules make passwords easier to guess, not harder?
answer
- who is doing the inventing
- four forced inventions every year
- a constraint narrows a space
- template, not entropy
- screen at set time instead
basics
~10 sA human forced to invent a compliant password four times a year converges on a template: a season, the year, one capital, one symbol. That template is a short candidate list to spray.
solid answer
~50 sComposition rules and forced expiry are both constraints on a human inventor, and humans satisfy constraints in the cheapest way that passes. Demand an uppercase letter, a digit and a symbol, then demand a new one every quarter, and the population converges on `Season+Year+!` and `Month+Year+#`, or on incrementing a digit on the previous choice. Complexity rules therefore do not add entropy; they *narrow* the region of the space where real passwords sit, and rotation refreshes the narrowing on a predictable schedule that an operator can read off a calendar. NIST SP 800-63B recognised this: verifiers should not impose composition rules and should not force periodic expiry, and should instead screen chosen passwords against a corpus of known-compromised values and force a change only on evidence of compromise. Rotation's original purpose — bounding how long a silently stolen password stays useful — is not served by a 90-day cycle against an operator who uses the credential the same afternoon.
go deeper
Be able to name the template a rotation policy produces — season or month, year, one symbol — and say why an attacker guessing at breadth loves it.
Explain the mechanism: a constraint narrows the region where real choices land, and forced re-invention refreshes that narrowing on a schedule. Know that NIST SP 800-63B drops both composition rules and arbitrary expiry.
Be ready to design the replacement — screening at set time, real minimum length, organisational-string ban, change on evidence of compromise — and to defend dropping rotation to a sceptical audience.
Own the argument that a control which shapes human behaviour must be evaluated on the behaviour it produces, not on the intent behind it, and be able to make that case where a checklist says otherwise.
## The rule is a recipe, and people follow recipes A password policy that requires an uppercase letter, a lowercase letter, a digit and a symbol is usually described as making passwords stronger. Arithmetically it does the opposite of what it claims. It does not add entropy to a human's choice; it *removes* the choices that fail the rule, and then human convergence removes almost everything else. What survives is a small set of shapes that satisfy every clause with minimum effort: a capitalised word, a two- or four-digit year, one trailing punctuation mark. Add a 90-day expiry and the effect compounds. Now the user must perform that invention four times a year, always under time pressure, always at a prompt they did not plan for. The two overwhelmingly common strategies are: - **The calendar template.** `Spring2026!`, `Summer2026!`, `Autumn2026!` — self-refreshing, always compliant, always memorable, and predictable to anyone who owns a calendar. - **The increment.** `Passw0rd7!` becomes `Passw0rd8!`. Formally a new password; in guessing terms, a one-character neighbour of the old one. Both are gifts to a spraying operator, whose entire attack is a short candidate list applied at breadth. The policy did not just fail to stop the attack — it *manufactured the candidates*. ## What rotation was originally for, and why the reasoning expired Periodic expiry came from an era of offline guessing against stolen hash files: if recovering a password took months, changing it every few months meant the recovered value was stale by the time it worked. Two things ended that reasoning. Guessing hardware collapsed the recovery time, and modern credential theft is not slow — a replayed or captured credential is used in hours, not months. A 90-day window bounds nothing that an attacker in your estate today cares about. ## What the published guidance actually says NIST SP 800-63B is the specification most often cited here, and it is worth being precise about its position: - Verifiers **shall not** impose composition rules on memorised secrets. - Verifiers **shall not** require arbitrary periodic change; a change is required **on evidence of compromise**. - Verifiers **shall** compare a candidate secret against a list of values known to be commonly used, expected or compromised, and reject a match. - Minimum length is a real requirement, and long passphrases must be accepted rather than truncated. Read as a set, that is a coherent repricing of the whole problem. Screening removes the strings that make stuffing and spraying pay. Length raises the cost of guessing generally. Compromise-triggered change replaces a calendar with a trigger that has actual information behind it. Composition rules and expiry are dropped because they push humans toward templates and buy nothing in return. ## The reviewer's version of this answer The chair you are usually sitting in is the reviewer told: *"we enforce complexity, 90-day rotation and five-attempt lockout, so guessing is handled."* All three claims can be true and the estate still be sprayable, because each control is aimed at a different attack from the one being run: | Stated control | What it actually bounds | Effect on a spray | |---|---|---| | Complexity rules | the shape of the string | narrows the candidate list in the attacker's favour | | 90-day rotation | how old a password may be | refreshes the template on a schedule | | Five-attempt lockout | guesses against one account | untouched; a spray sends one | The replacement set is short and unglamorous: a breached-password screening check at set time, a genuine minimum length with passphrases allowed, a ban on the organisation's own strings, and a forced change only when there is reason to think a specific credential is compromised. ## The nuance worth keeping None of this means passwords should never change. It means the trigger should carry information. A credential that appears in a new corpus, an account that shows a sign-in the owner disowns, a shared secret after a team member leaves — all are real triggers. A quarter boundary is not one, and treating it as one costs you the entropy of every human choice in the estate.
- Rotation was meant to bound how long a stolen password stays useful. What replaces that?A change triggered by evidence about a specific credential — it appears in a new breached-password corpus, or the account shows use its owner disowns. That trigger carries information; a quarter boundary does not. And against an operator who replays a credential the same day, a 90-day window bounds nothing at all.
- Is raising the minimum length just a bigger version of a composition rule?No. A composition rule constrains which characters must appear and thereby narrows where human choices land. Length multiplies the space without dictating shape, and it makes passphrases the path of least resistance rather than templates. The pairing that works is a real minimum length plus screening against known-compromised values, with no composition clauses at all.
- A team argues that banning a rejected-password list is the same as breach screening. Are they equivalent?No. A hand-maintained banned list holds tens or hundreds of strings the organisation thought of. A breached-password corpus holds hundreds of millions of strings that real humans actually chose, which is the same population a stuffing operator is replaying. Only the second one intersects the attacker's input.
Telling ten thousand people to invent a new secret every quarter, and it must have a capital and a symbol, is a recipe. People follow recipes, and a recipe has a short list of outputs.
saying these in an interview costs you the question
- Says complexity rules add entropy to a human choice
- Claims 90-day rotation meaningfully limits attacker access time
- Treats a small banned-word list as equivalent to breach screening
- Assumes users pick uniformly at random within the allowed space
- Argues rotation must stay because an audit checklist names it