Passwords historically got weaker over time, but not in the sense that 'if he got your password hes not going to wait to use it'. They weaken in their hashed form. It used to be (still is, really) trivial to score the passwd file of a system, and get all the hashes of passwords, but no plaintext.
By changing passwords every N months, you eliminated the ability of someone to crack the hashes and obtain a cleartext password where they previously only had a hash.
That time window has gotten absurdly short, however...and with Pass the Hash and MITM, I don't even need your password anymore :(
By changing passwords every N months, you eliminated the ability of someone to crack the hashes and obtain a cleartext password where they previously only had a hash.
That time window has gotten absurdly short, however...and with Pass the Hash and MITM, I don't even need your password anymore :(