I have to agree with witkovsm
As an employee of a company that requires password changes every 45 days, I just end up using the same password with a different number at the end. It's hard enough to come up with a strong, unique password THAT I CAN REMEMBER (most companies frown on writing down your password and keeping it anywhere you can easily access it). How is the average employee supposed to do this every 30-45 days? I get the theory behind frequently changing passwords, but in my experience, the reality is completely different.