Loughborough University
Leicestershire, UK
LE11 3TU
+44 (0)1509 263171
Loughborough University

IT Services - Staff

Registration, Passwords, and De-registration

Photo: Lady smiling.

Password Guidance

What makes a good password?

A good password should contain 8 characters or more, with at least three, preferably all, of the following:

From August 23rd 2006, when you change your normal University (Active Directory password), you will need to select one that meets all of the following criteria:

Why are passwords so important?

They are the first line of defence against attacks on your computer. If someone has or can guess your password, it gives them access to all your files and, potentially, all the files of other users of the same services. By choosing a good password you can help not just to protect your computer files but those of all other users. Someone who tries to break in to computer systems by cracking passwords is often called a cracker. If a cracker cannot interact with your system, then they have almost no avenues of attack left open to break your system.

If a cracker can, by some means, read your stored passwords, it is vital that they are not able to break any of them. If they can, then they are able to:

  1. log on to your system, and can then

  2. become "super-user" or a system administrator via an operating system hole.

Other elements of good practice can be summarised as:

  1. Don't use your login name in any form (as-is, reversed, capitalised, doubled, etc.).

  2. Don't use your first, middle or last name in any form, or your initials or nicknames; or anyone else's.

  3. Don't use your spouse's, child's or pet's name.

  4. Don't use other information easily obtained about you. This includes license numbers, telephone numbers, social security numbers, the make of your car, the name of the road you live on, the name of your favourite band or sports team etc. Someone who knows you can very easily guess such passwords.

  5. Don't use a password of all digits, or of all the same case letter. This significantly decreases the search time for a cracker.

  6. Don't use a word contained in any dictionary, in any language, spelling lists, or any other list of words or abbreviations.

  7. Don't use a password with fewer than eight characters.

  8. Don't use dates such as September, SEPT2005 or any similar combination.

  9. Don't use keyboard sequences, e.g. qwerty.

  10. Don't use a sample password, no matter how good, that you have obtained from a book or web site that discusses information and computer security.

  11. Don't write a password on a post-it note, desk blotter, calendar, or store it online, or anywhere others can access it.

  12. Don't reveal a password to anyone, except a trusted member of IT staff.

  13. Don't use any of the above otherwise disguised, e.g. with "0" (zero) for "o", "1" (one) for "I" and so on.

  14. Do use a password with mixed-case alphabetic characters.

  15. Do use a password with non-alphabetic characters, such as digits or punctuation.

  16. Do mix up numbers, letters and non-alphanumeric characters.

  17. Do use a seemingly random selection of letters, numbers and non-alphanumeric characters.

  18. Do use a password that is easy to remember, so you don't have to write it down.

  19. Do use a password that you can type quickly, without having to look at the keyboard. This makes it harder for someone to steal your password by watching over your shoulder ("shoulder surfing").

  20. Note: Please remember to take account of the variations between keyboards. For example, on a Macintosh the '#' (hash) character requires three keystrokes.

  21. In addition you should not use passwords which are dictionary words and then end with just numbers or punctuation. This increases the speed at which the password can be cracked.

  22. Dictionary substitution of characters (e.g. replacing 'a' with '@' or 'B' with '8') will not slow down a password cracking attempt and should be avoided.

  23. The use of '&' should also be avoided along with the use of '#' on Apple Macintosh machines (where it requires three keystrokes).

Methods for choosing secure, easy to remember passwords

Choose a line or two from a song or poem, and use the first letter of each word

For example, taking the first two lines from the well known poem, Xanadu, by Samuel Taylor Coleridge:

"In Xanadu did Kubla Khan
A stately pleasure dome decree:"

could give the password: "IXdKkaspDd:" - Capital I Capital X lower d Capital K lower k lower a lower s lower p Capital D lower d Colon.

"1XdKk@$pDd:" One Capital X lower d Capital K lower k at-sign dollar-sign lower p Capital D lower d Colon.

Some Other Examples, following the same method
N>kFfmp,D No more Krazy Frog for me please, Darling
LB@tgB1tw Led Bib are the greatest band in the world
8JSianG,y But John Sergeant is a nice guy, yes
1dkA@5aA I don't know anything about soaps at all
DW1@Qwp,D Dr Who is a quite wonderful program, Davros
H0Ew1l,wDH How on EARTH will I live, without Desperate Housewives

Some additional password advice is provided as part of IT Services' Introduction to Security course at www.lboro.ac.uk/it/security/security-intro.html#password.

To change your password now, go to Password Changing https://pass.lboro.ac.uk/.

Search



Getting Help

Tel: 01509 22 2320
IT.Services@lboro.ac.uk

IT Service Desk
Level 3 (top floor)
Haslegrave Building

9:00am to 5:30pm Monday to Thursday and 9:00am to 5:00pm on Friday.

You can also seek help at any time via our Getting Help section.