Some of the password advice we all grew up with is not just outdated. It actively makes your accounts weaker while feeling responsible. You change your password every 90 days, you cram in symbols, you follow the little “strength meter” that turns green, and you assume you are safe.

Meanwhile the guidance from the people who actually study this has quietly changed. The rules flipped years ago, and most of us never got the memo. Here are the myths worth letting go of, and what actually protects you instead.

Key takeaways

  • Forcing password changes every few months makes people pick weaker, more predictable passwords.
  • Length protects you more than symbols and mixed case ever did.
  • The green “strength meter” measures shape, not whether your password has already leaked.
  • Complexity you cannot remember pushes you toward reuse, which is the real danger.

Myth: you should change your password every few months

For years, workplaces demanded a new password every 30, 60, or 90 days. It sounded diligent. In practice it backfired.

A wall calendar with a date circled in red marker
Forced password expiry dates push people toward weaker, predictable choices.

When forced to change constantly, people do the least effort thing: they turn “Summer2024” into “Summer2025,” or add a “1” and then a “2.” Attackers know this and guess the next variation easily.

Modern guidance from the US National Institute of Standards and Technology now advises against routine forced expiry. You should change a password when there is a reason, such as a breach or a shared login, not on a calendar. You can read their plain-language take at the US cybersecurity agency site, which echoes the same advice.

Good to know

The one time you absolutely should change a password immediately is when it shows up in a breach. That is a reason, not a routine. Everything else can stay put as long as it is long and unique.

Myth: symbols and mixed case make a password strong

We were taught that a “strong” password needs an uppercase letter, a lowercase letter, a number, and a symbol. So people built things like “P@ssw0rd!” and felt protected.

The problem is that short-but-complex passwords are still short. Cracking software chews through them quickly because there are not enough characters, no matter how many symbols you sprinkle in.

What actually slows an attacker is length. A password of five random words, even in plain lowercase, has so many possible combinations that guessing it is impractical. If you want the method spelled out, our guide to making strong passwords you can remember walks through it.

Why the strength meter lies to you

Those colored bars that go from red to green only measure the shape of what you typed: length, character types, obvious dictionary words. They cannot see the one thing that matters most.

A meter will happily flash green for a password that has already leaked in a major breach and sits in every attacker’s guess list. Shape looks strong; reality is broken. Meters are a rough hint, not a verdict.

Myth: complex passwords are always safer than simple ones

Here is the trap. The more complex and random a password is, the harder it is to remember, and the harder it is to remember, the more tempted you are to reuse one “good” password everywhere.

Reuse is the actual catastrophe. One breached site then opens the door to your email, your bank, and everything else. A slightly less exotic password that is unique to each account beats a fiendishly complex one you recycle. Our reader questions on password reuse danger explain exactly how attackers exploit that.

Tip

Let a password manager generate and store the truly random, complex passwords. Then complexity costs you nothing, because you never type or memorize them. You only remember two or three passwords by hand.

Myth: hackers are personally targeting me

Most people picture a hooded figure typing furiously to break into their specific account. That is rarely how it works for ordinary people.

The common threat is automated and impersonal. Attackers buy huge lists of leaked email-and-password pairs and run software that tries them against thousands of sites at once. You are not singled out; you are one line in a spreadsheet.

This is oddly reassuring, because the defense is straightforward. A unique password per account means your line in that spreadsheet opens nothing else. You do not have to outsmart a genius, just avoid the automated dragnet. Our rundown of common password mistakes and their easy fixes covers the habits that put you on those lists in the first place.

What the rules actually say now

It helps to see the old myth and the current advice side by side, so you know what to keep and what to drop.

Old myth What guidance says now
Change passwords every 90 days Change only when there is a reason, like a breach
Symbols and mixed case equal strength Length matters most; aim for 16 or more characters
A green meter means you are safe Check if the password has actually leaked
One very complex password is enough Every account needs its own unique password
Hackers target you personally Most attacks are automated and impersonal

What to do instead

Dropping the myths is not about doing less. It is about spending your effort where it counts.

Make your important passwords long and unique, one per account. Let a password manager remember them. Turn on two-factor authentication so a leaked password alone cannot get in. And instead of a calendar reminder to rotate passwords, set up a habit of checking for breaches.

When I finally stopped forcing quarterly changes on my own accounts and switched to long unique passphrases, my logins got both safer and less annoying. That combination is rare, and it is the whole point. For the wider foundation, our overview of password security basics ties it together.

Your afternoon checklist

  • Turn off any self-imposed rule to change passwords on a schedule.
  • Rewrite your key passwords as long strings of random words.
  • Install a password manager to hold the truly complex, random ones.
  • Give every account its own unique password over the next few weeks.
  • Turn on two-factor authentication for email and money accounts.
  • Check your email on a breach-lookup service instead of trusting strength meters.
  • Change a password only when it leaks or you shared it, not on a timer.

Old habits die hard, especially the ones that felt responsible. But letting go of these five will save you effort and make you safer at the same time. Spend that reclaimed energy on length and uniqueness, and you are ahead of most people.