Home | Apply To SGU | Request Information | Attend Information Session | SGU Apparel | Contact Us
Analogy - A Password Is like a key
Passwords have become such a part of our daily life that we treat them with indifference. As a result we end up sacrificing security for convenience. Often we use weak passwords that are easy for someone else to guess. A weak password is a simple word or phrase, often connected to the user in some readily discernable fashion (a child’s name, a favorite travel destination). Conversely, passwords which are complex and impossible to guess may be useless for security. What good are complex passwords if you are unable to remember them? Hard to remember passwords can lead to unwise security shortcuts. Have you ever seen someone try to recall a password, and then lift up their keyboard or open their desk drawer to consult a sticky note secured there? We store such password cheats on our desktops, in our wallets, tacked to our bulletin boards or taped to computer screens.
Think of how you handle your house keys. You don’t leave them lying around, you don’t make them accessible to strangers and you often install multiple locks to secure your front door. Your password is like a key, in that it opens the door to vital University data. It would be much easier and much less suspicious for the intruder to let themselves in your house with a key than breaking in the front door. Similarly, it is much easier for an intruder to gain access to our network with a valid password than if he tried to bypass security on his own.
Dictionary programs are just one tool used by hackers to crack passwords. Computing speeds allow a hacker to post every word in a dictionary (English, foreign language, slang) through a login program hoping that a word will eventually match a simple password. Once the password is discovered, the hacker can use it to gain access to secure information or to cover his or her tracks on the way to another target. The problem extends beyond the personal loss of data. In our networked age, if your password is stolen, you will not be the only one affected. Therefore, we need to view passwords as digital keys to University resources with the understanding that there could be serious consequences if these keys can be easily guessed or stolen. This means you need to be wise in how you choose your passwords.
Password Complexity Rules
All passwords must meet the following complexity guidelines:
The password MUST:
The password MUST NOT:
Mnemonics help us select a strong, complex password that we won’t forget.
Your password should be (a) easy for YOU to remember, (b) hard for someone who sees it to remember, and (c) hard for anyone to guess.
We can use a mnemonic device (a memory trick that helps us recall something) to create a complex password that is also easy to remember. For example, we can create a password from the first letters of an easily-remembered phrase, poem, or song lyric. The phrase “Jack and Jill went up the hill,” results in the password “ J&Jwuth”. Note that this password is seven characters long and contains upper case, lower case and special characters. For mnemonic passwords to be useful, the phrase must be easy to remember.
How to Choose a Good Password:
Example: for those about to rock, we salute you
Resulting password: 4tatRwsu
Adjusting passwords for other accounts
How can you adjust the password to use it for other accounts? You can add a character to the beginning or end of the password that relates in some way to the site or service you need the password for (or if length is an issue, replace one of the characters). Using the example password created above, replace the ‘W’ from the word ‘we’ with the first letter of the name of the site or service. So the phrase in my head might end up sounding like this “For Those About to Rock, Amazon Salutes You” which would translate to 4tatRAsu (I’ll capitalize the letter since the names will usually be proper names, and it should make the password even stronger). Here are a few more examples:
Examples of Memorable Phrases and Passwords
| Phrase | Password | Inspiration |
Four score and seven years ago, our Fathers |
4s&7yaoF |
Quotation – Gettysburg Address |
I love to ski at Seven Springs! |
Ilts@7S! |
Personal – Hobby |
Ali Baba and the forty thieves |
AB&t40t |
Old movie |
Yankee Doodle went to town |
YDw2town |
Song |
I love Paris in the springtime replace L with the number 1 |
1LpinST |
Expressions inspired by the name of a city |
Come up with a phrase that means something to you, such as an old address |
3TowerRoadBoston |
no-one but my immediate family would recall |
Please do not use these examples for your actual password!