Passwords don't go stale and hackers don't spend 90 days trying to guess your password. There is a totally different reason why some companies have a password expiration policy and it doesn't apply to individual internet users. The way I understand password expiration policy is that hackers will try to crack a password to create backdoor access for ongoing information theft. Scheduled pw changes theoretically limit that access time. I don't think the policy makes sense there either. People will most likely use a slight variation of their old password, use postit notes on their monitor, or forget the new pw and an admin will have to come in and fix it. And 30 to 90 days is a
long time.
But... if it makes you
feel more secure then have at it
Cool article on passwords.