I believe the main concern for periodic password changes is that most people won’t take the time to generate unique passwords each time. They will typically iterate a password over time, meaning a couple leaked passwords will narrow down guesswork to a trivial number of guesses and remove the benefit of the timed changes.
NIST no longer recommends password expirations except for cases where it is believed that a breach occurred.
I believe the main concern for periodic password changes is that most people won’t take the time to generate unique passwords each time. They will typically iterate a password over time, meaning a couple leaked passwords will narrow down guesswork to a trivial number of guesses and remove the benefit of the timed changes.
NIST no longer recommends password expirations except for cases where it is believed that a breach occurred.