Change Your Password Day: When a Change Actually Helps

February 1 is a chance to check your accounts. Which passwords need replacing, which can stay, and where do password managers, extra factors and passkeys fit in?

Pixel-art illustration for “Change Your Password Day”

February 1 is known as Change Your Password Day. It is a useful reminder to check your accounts, but the name can suggest the wrong task. Replacing a familiar password with its next predictable variation is not much of an upgrade. Start by asking what needs fixing.

When should you actually change a password?

Change it when it has been exposed or you have a credible reason to suspect that it has. Replace weak passwords and any that you use across multiple services, too. A strong, unique password does not need replacing just because another month has passed. The current NIST guidelines explicitly reject mandatory periodic changes without a reason.

If a service reports a breach affecting your credentials, follow its guidance and secure that account. Replace the password everywhere else you reused it. When several accounts need attention, give your main email account particular priority: it often controls password resets for other services. Open the familiar website or app yourself instead of following a password-reset link in a suspicious message.

Give every account its own key

Imagine the key to an old forum also opening your mailbox and front door. Reusing a password creates that kind of connection. Separate passwords help contain the damage when one service loses control of its credentials.

Length and unpredictability matter more than cosmetic changes such as an exclamation mark at the end. NIST's explanation of password strength describes why complicated-looking patterns are not automatically strong. Adding punctuation to your hamster's birthday does not make it random.

Let a password manager handle the collection

You do not need to memorise dozens of cryptic strings. A password manager can generate long, random passwords and store them securely. Germany's BSI recommends separate passwords for each account and identifies password managers as a useful aid.

Mashing keys is not a reliable substitute for a password generator, and an unencrypted Word document is not a suitable password vault. Use your manager's generator, protect access with a strong master password and carefully set up the recovery options it provides.

Add another layer, or use a passkey

Enable multifactor authentication for important accounts. Signing in then requires something beyond the password, such as an authenticator app or a security key. Keep recovery codes somewhere safe so that losing a device does not lock you out permanently.

If a service supports passkeys, consider that sign-in option. As the UK National Cyber Security Centre (NCSC) explains, passkeys replace passwords with cryptographic keys and are designed to resist phishing. Check how you will recover access or move to a new device before relying on them.

A better February 1 checklist

Choose one important account. Does it have a unique password? Is a second factor enabled? Are its recovery details still correct? Address real weaknesses first. A useful security check leaves you with better-protected accounts, rather than a longer list of passwords changed for the sake of it.

For a less serious entry in the nerd calendar, you can turn to our story about Beer Can Appreciation Day.

Content revised on September 19, 2026. The earlier blanket advice to change passwords regularly and avoid storing them has been corrected.


Your daily side quest

Every day has lore.

Explore the Nerd Calendar and discover the anniversaries, releases and gloriously odd celebrations hiding in plain sight.

Explore today’s nerdy events

Follow the signal

Nerdy talk between posts.

Short takes, fresh finds and the occasional deeply unnecessary fact — transmitted on X.

Follow NerdSpot on X