The main reason for changing passwords periodically is to reduce the window of opportunity during which a compromised password can be exploited.

Of course, most compromised passwords will be used immediately after they have been compromised, so changing passwords every 30/60/90 days is pretty pointless. However, the user has to remember yet another password - and is quite likely to choose a less secure one in the haste to satisfy the password-reset requirement.

Good to see some sensible advice being provided.

