Security – security benefit to a regular changing password policy

passwordSecurity

I've found in several cases, forcing users to change their password on a regular basis becomes more of a strain on maintenance rather than a help for security. Also, I've seen users write their new passwords down since they either don't get enough time to remember their passwords and can't be bothered re-learning another one.

What security benefit is there for forcing a change in passwords?

Best Answer

Here is a different take from the SANS diary:
Password rules: Change them every 25 years

There is one practical benefit. If someone has your password, and all they want is to read your email and remain undetected, they can do so forever, unless you eventually change your sign-in secret. Thus, regularly changing the password doesn't help much against someone breaking in and making it off with your goods, but it DOES give you a chance to shake off any stalkers or snoopers you might have accessing your account. Yes, this is good. But whether this benefit alone is worth the hassle and mentioned disadvantages of forcing users to change their password every 90 days, I have my doubts.