I believed it until your password remark. That's a bad, bad practice.
I think the above commenter is thinking about the requirement a user to change a password on a timed basis. There's been a good bit of research done in this area, and the consensus is that it just causes most people to stick a number at the end of their password anyway, making the policy completely worthless at best, but it often leads to people writing their passwords down.
https://www.nist.gov/itl/tig/projects/special-publication-80...