Is your password “123456”? Worst passwords list revealed…
16/11/2016
In SplashData’s fifth annual worst passwords list, “123456” and “password” remained the top passwords in 2015. Does your password appear on the list? Thinking up a password for a new service (or changing your password for an existing service, which should be done at least annually) is a real pain. On top of that, sites often have different and unclear requirements about password length and the use of numbers and special characters.
However, the importance of good passwords can’t be denied, especially for University accounts. Your network password gives access to a wide range of systems and services, and protects all your files, including any research data stored on the network. If your research contains valuable or sensitive data, perhaps commercial data, it is even more important to protect it well with a strong password (and encryption if necessary – see more on our data security intranet page).
A password that is easy to remember but hard to guess can be difficult to create, so here are some top tips around password security:
- Whilst the cartoon on this post amusingly demonstrates that long passwords aren’t always hard to remember, the example isn’t quite an acceptable network password. You should use a mix of uppercase and lowercase letters, numbers, and special characters.
- Regarding length, passwords should never be shorter than 8 characters, and once you hit 15 characters, even automated programs that try all character combinations struggle.
- A good method we recommend is to use the first letter of each word in a memorable phrase, saying, nursery rhyme or song title. For example, Do you know the way to San Jose? = Dyktw2SanJose?
- Try to ensure you can type your password quickly (e.g. using words that alternate between left- and right-handed keys on a keyboard). Shoulder-surfing, where people steal your password by watching you type it in, is a growing concern.
- Use different passwords for different services wherever possible, and don’t forget that the Cranfield Network Password Policy (pdf, internal-only) requires you not to use your University password for non-University accounts. (We don’t know how securely other services store passwords.)
So why not take a moment to check your passwords are safe? You can change your network password and security questions using our Password Manager, and learn more tips on our Information Security intranet site.
Image from XKCD at http://xkcd.com/936/, CC-BY-NC 2.5
Categories & Tags:
Leave a comment on this post:
You might also like…
My Apprenticeship Journey – Broadening Horizons
Laura, Senior Systems Engineer at a leading aircraft manufacturing company, joined Cranfield on the Systems Engineering Master’s Apprenticeship after initially considering taking a year off from her role to complete an MSc. Apprenticeship over MSc? ...
The Library app is back!
The Library app is back! It's exactly the same as before (although it will get a fresh look in a few months) and if you hadn't removed it from an existing device it should just ...
PhD researcher at the IF Oxford Science and Ideas Festival
IF Oxford is a science and ideas Festival packed with inspiring, entertaining and immersive events for people all ages. PhD researcher, Zahra attended the festival. Here she shares what motivated her to get involved. ...
What leadership skills are required to meet the demands of digitalisation?
Digital ecosystems are shifting the dynamics of the world as we know it. With digitalisation being a norm in the software industry, there is currently a rapid rise in its translation ...
My PhD experience within the Centre for Air Transport at Cranfield University
Mengyuan began her PhD in the Centre for Air Transport in October 2022. She recently shared what she is working on and how she has found studying at Cranfield University so ...
In the tyre tracks of the Edwardian geologists
In April 1905 a group of amateur geologists loaded their cumbersome bicycles on to a north-bound train at a London rail station and set off for Bedfordshire on a field excursion. In March 2024 a ...