Straight answers on hard choicesLast filed Sep 8, 2026

Tech

New Password Advice Every Few Months? Three Tests for Deciding What Applies to You

Password guidance keeps changing, and most of it is written for an average week nobody actually has. Here is how to judge which advice is yours.

Tech||Bram Voskuijlen

A kitchen table with a laptop open to a login screen, a phone displaying a six-digit verification code, and a printed sheet of backup codes beside a coffee cup
A kitchen table with a laptop open to a login screen, a phone displaying a six-digit verification code, and a printed sheet of backup codes beside a coffee cup

Password advice arrives in bulletins. A breach makes the news, an employer pushes a new policy, a phone update starts offering to generate something unreadable and store it somewhere you have not looked at yet. Each piece of guidance sounds reasonable in isolation, and most of it is, but almost none of it tells you whether it is aimed at you, at a bank's fraud department, or at an administrator holding keys to a server room. The useful skill is not memorizing rules. It is deciding, quickly and without much anxiety, which rules are yours to follow.

Start with the week you actually have, not the one the advice assumes

Guidance tends to imagine a person who logs in deliberately, at a desk, once per account. The real week is different. You sign into a payroll portal on Monday because a form is due, you let a browser fill a shopping site you last used in the spring, you read a utility bill on a phone in a parking lot, and someone in the house asks for the streaming login by text. Most of those logins are handled by autofill, which means you have not typed the password in months and could not recall it under pressure. That is not sloppiness. It is what the tooling was built to produce, and any advice that ignores it will not survive contact with a Tuesday.

So write down, roughly, what a fortnight of logins looks like. Not every site: the ones that recur, the ones tied to money, the ones shared with another person, and the two or three you reach for only when something has gone wrong. That short inventory is the thing new advice gets tested against. Without it, every recommendation feels equally urgent, and equally easy to postpone.

Sort accounts by what a failure costs, not by how important they feel

The instinct is to rank accounts by sentiment: the bank feels serious, the recipe site feels trivial. Consequence is the better sort. Ask what someone gains by holding the account for an hour, and what it takes to get it back. Email and phone accounts sit at the top, not because of what they contain but because they are the route through which every other reset runs. Anything holding a stored card or a bank connection comes next. Then employer systems, where the damage lands on other people and on a policy you did not write.

Below that sits a long tail where reuse is a nuisance rather than a catastrophe, and where a leaked password mostly means spam. Being honest about that tail is what makes the top of the list manageable. You are not going to give sustained attention to two hundred accounts week after week, and pretending otherwise is how people end up giving sustained attention to none of them. Protect the recovery layer properly, protect the money layer properly, and let the rest run on generated passwords you never see.

Three questions that settle most new advice

First: what threat is this rule aimed at, and does that threat reach me? Rules about frequent rotation were largely aimed at shared credentials inside organizations, and when applied to a household they produced predictable variations on one word, which is worse than leaving a strong password alone. The National Institute of Standards and Technology is the body responsible for federal digital identity guidance in the United States, and the broad direction of that work has been toward length, uniqueness and screening against known-compromised passwords rather than forced complexity and calendar-driven change. That shift is the clearest signal available that some familiar habits were solving a problem most people never had.

Second: what does this cost me every week, and will I still be doing it in March? A rule that requires ten seconds at each login survives. A rule that requires you to look something up in another room does not, and its collapse usually takes something else down with it, because you start working around the system instead of inside it. Third: what happens on the bad day? If your phone is lost, if the laptop is stolen, if the manager is locked and the second factor lives on the missing device, does the arrangement have a way back that does not depend on the thing that failed? Advice that has no answer to that question is incomplete, whoever issued it.

The habits that hold up under an ordinary bad day

What tends to survive is small. A single strong, memorized passphrase for the account that unlocks everything else, long rather than clever, never used anywhere a website could leak it. A second factor on email, on the phone carrier account and on anything financial, with backup codes printed and kept where you keep the car title, because that is the piece almost everyone skips and the piece that decides how a lost phone plays out. Everything else generated, stored, and forgotten on purpose. Recovery contacts and recovery email addresses checked once a year, since a stale one quietly turns a five-minute reset into a week of arguing with support.

Then a review that fits in one sitting, twice a year, not a rolling anxiety. Look at what your manager or browser reports as reused or exposed, fix the ones sitting near money or recovery, and close accounts you have stopped using rather than maintaining them. Judgment here is mostly a matter of knowing which twenty logins matter and declining to spend attention on the other hundred and eighty.

The advice will keep changing, because the attacks keep changing and the guidance is honest enough to follow. What makes the changes easy to absorb is having your own list, your own ranking, and a habit of asking what any new rule costs you between now and next spring. That is portable. It works on advice that has not been written yet.

More from this edition