This practice is not recommended anymore, yet still found in many enterprises.

  • Forever is vulnerable to phishing attacks, same reason why monthly is getting discouraged. Monthly is weaker because the average person does slight variation, which attackers LOVE.

    • Frequent password changes don’t protect against phishing.

      And while a high frequency like monthly changes will probably result in even weaker passwords, also yearly changes will make people choose weak passwords.