What are some tips for creating strong and unique passwords?

  • Thread starter Thread starter scott1
  • Start date Start date
Click For Summary

Discussion Overview

The discussion revolves around strategies for creating strong and unique passwords, addressing challenges users face with password management, security policies, and various methods to remember or generate passwords. The scope includes personal experiences, technical requirements, and suggestions for improving password security.

Discussion Character

  • Exploratory
  • Debate/contested
  • Technical explanation

Main Points Raised

  • Some participants mention the difficulty of remembering multiple passwords, leading them to use a few common ones or resort to writing them down.
  • There are varying password policies at different institutions, with some requiring frequent changes and restrictions on reusing old passwords, which complicates memory.
  • One participant suggests using long, random sequences of characters as passwords, while others discuss the challenges of creating memorable yet secure passwords.
  • Some propose using a main password and customizing it for different sites as a strategy to manage multiple passwords.
  • There are humorous remarks about the absurdity of password requirements and the idea of using unconventional methods, such as letting a cat walk across the keyboard to generate passwords.
  • Several participants express frustration with complex password requirements that make it hard to remember passwords, especially for infrequently used accounts.

Areas of Agreement / Disagreement

Participants generally share similar frustrations regarding password management and security policies, but there is no consensus on the best approach to creating or remembering passwords. Multiple competing views on effective strategies remain present.

Contextual Notes

Some participants note specific limitations in their password management strategies, such as the inability to remember passwords due to frequent changes and complex requirements. There are also references to varying institutional policies that affect password creation.

scott1
Messages
353
Reaction score
1
According to Kim-Phuong Vu, a lot of users try to remember half a dozen passwords. Which is why the most common password is "password."
http://www.ddj.com/blog/securityblog/archives/2006/05/password_protec.html"
How did they know my password that I use for everthing:confused:
 
Last edited by a moderator:
Computer science news on Phys.org
I have about 3 or 4 passwords that I use for nearly everything. I plan on changing them soon though, as they have been the same for quite a while.
 
They recently changed things at our university to require changing passwords every 6 months, and you can't reuse the last THREE passwords. I can't remember that many! So, I've taken to creating stickies on my computer for the ones I don't really give a darn about. So much for improving security. :rolleyes: That, or I just keep changing one number...I figure I can just rotate 1 through 4 and then start over again.
 
Moonbear said:
They recently changed things at our university to require changing passwords every 6 months, and you can't reuse the last THREE passwords. I can't remember that many! So, I've taken to creating stickies on my computer for the ones I don't really give a darn about. So much for improving security. :rolleyes: That, or I just keep changing one number...I figure I can just rotate 1 through 4 and then start over again.

lol Moonbear. They made me do that when I worked at the LIBRARY! :rolleyes:
 
my passwords are 16 digits long :biggrin:
and no its not my debit/credit card numbers, i just like remembering random sequences of alpha-numeric-symbol combinations
 
Physics_wiz said:
lol Moonbear. They made me do that when I worked at the LIBRARY! :rolleyes:
:rolleyes: I just have to laugh, or else I'd cry, since they still manage to have security holes a mile wide, but by gum, you better change your password every 6 months.

Glad you popped back into GD...I just met SpaceTiger today, and will be meeting up with Russ Watters later in the week, and still need to meet one more PFer to tie with the Oregon mentors' record gathering of 4. We should meet up around campus sometime! :biggrin:
 
Our passwords expire every thirty days and none can be reused for 12 months and they require a combination of upper and lower case letters, at least one number and a special character, and there are dozens of systems that require different passwords, so we all keep a page long password cheatsheet at our desks because in their misguided attempt at security, they've made it impossible to remember passwords to systems we don't use daily. I can go to anyone's desk and log in as another person.
 
Moonbear said:
Glad you popped back into GD...I just met SpaceTiger today, and will be meeting up with Russ Watters later in the week, and still need to meet one more PFer to tie with the Oregon mentors' record gathering of 4. We should meet up around campus sometime! :biggrin:

Sure :biggrin: it doesn't look like I'll be going away this summer...no internships for me :frown:
 
One word: biometrics
 
  • #10
No matter what password i use it all ways comes out to be ******, :confused:
 
  • Haha
Likes   Reactions: BillTre
  • #11
wolram said:
No matter what password i use it all ways comes out to be ******, :confused:
:smile: Sometimes mine are dots instead of asterisks. :biggrin:
 
  • #12
Evo said:
Our passwords expire every thirty days and none can be reused for 12 months and they require a combination of upper and lower case letters, at least one number and a special character
I had to register on a site for submitting grants recently that had insane requirements like that...PLUS the added restriction that you couldn't have a number as the first or last character. And it's the sort of site that you'd use once or twice a year, so yeah, there's no way I'll remember an unusual password for that. Of course, that's opposed to the scientific society I belong to that the challenge is remembering your username, because it's your membership number...they end up having to email everyone their membership numbers when it's time to submit abstracts and register for the meeting, because nobody can ever find the little card they mail with our number on it. But your password there is just your last name, and they tell you that right on the site. :smile:
 
  • #13
cronxeh said:
my passwords are 16 digits long :biggrin:
and no its not my debit/credit card numbers, i just like remembering random sequences of alpha-numeric-symbol combinations
I do all of mine on the basis of keyboard layout. Its easier for me to remember a sequence of spatial positions and hand movements than a semi-random set of 14 characters from my keyboard. Downside is I don't actually know some of my passwords. I just remember how to type them.

I actually started doing this because of the password requirements for our school email accounts that required at least one non-alphanumeric character, numbers and letters, etc. And it couldn't be a password someone else used. It was a pain in the ass to come up with a permissible one.
 
  • #14
Moonbear said:
They recently changed things at our university to require changing passwords every 6 months, and you can't reuse the last THREE passwords. I can't remember that many! So, I've taken to creating stickies on my computer for the ones I don't really give a darn about. So much for improving security. :rolleyes: That, or I just keep changing one number...I figure I can just rotate 1 through 4 and then start over again.
You could use:
password1
password2
password3
password4
password5
password6
etc.
 
  • #15
scott1 said:
You could use:
password1
password2
password3
password4
password5
password6
etc.
Hey! How'd you guess my passwords?! :smile:

Oh, I just remembered the password rules at another university...in addition to the requirements for capitals, lowercase, and combinations of letters and numbers, you couldn't include any word actually found in the dictionary! So, you either had to break the words up with numbers or symbols, or try to think up a whole sentence and use first letters of each word or something like that to try to create something you could actually remember.
 
  • #16
Enjoy the simple rules while they last. In a few years, all new employees who need passwords will be required to take a cryptography class first.
 
  • #17
Physics_wiz said:
Enjoy the simple rules while they last. In a few years, all new employees who need passwords will be required to take a cryptography class first.
:smile: :smile: :smile:

I think I just need to borrow someone's cat to walk across my keyboard to create my next password.
 
  • #18
An interesting way to keep track of passwords is to have one or two "main" passwords that you can easily remember and then customize it to each website.

For example if my main password was snow101 I would make it snow101pf for physics forums, snow101y for yahoo, snow101gm for g-mail, etc etc.

I don't actually do that though. It's just an interesting trick I read about.
 
  • #19
dav2008 said:
An interesting way to keep track of passwords is to have one or two "main" passwords that you can easily remember and then customize it to each website.

For example if my main password was snow101 I would make it snow101pf for physics forums, snow101y for yahoo, snow101gm for g-mail, etc etc.

I don't actually do that though. It's just an interesting trick I read about.

Whoever came up with this stole it from me!
 
  • #20
dav2008 said:
An interesting way to keep track of passwords is to have one or two "main" passwords that you can easily remember and then customize it to each website.

For example if my main password was snow101 I would make it snow101pf for physics forums, snow101y for yahoo, snow101gm for g-mail, etc etc.

I don't actually do that though. It's just an interesting trick I read about.
I started out doing that, and then they kept adding new twists and rules that made it more challenging, and then I don't remember what version I used (which one ends with 1, which with !, which with just the letters, which is split in the middle with a hyphen, which is on version 2, 3, 4 etc.)
 
  • #21
I just make up sentences or phrases and use the first (or second, last, etc.) letter of each word in it, throwing in some digits to replace letters, as a '1' for a 't', '2' for 'to/too/two', '4' for 'for', and such. I easily have 20 different ones, and they're all easy to remember because you can make the sentence or phrase be about the site or program that the particular password is for. You could also take lines from poems, songs, movies, and so on. For example, This is the password of J. Alfred Prufrock for Physics Forums = 1i1pojap4pf.
 

Similar threads

Replies
3
Views
5K
  • · Replies 24 ·
Replies
24
Views
11K
  • · Replies 76 ·
3
Replies
76
Views
9K
  • · Replies 6 ·
Replies
6
Views
2K
  • · Replies 4 ·
Replies
4
Views
5K
  • · Replies 21 ·
Replies
21
Views
3K
  • · Replies 4 ·
Replies
4
Views
3K
  • · Replies 17 ·
Replies
17
Views
3K
  • · Replies 17 ·
Replies
17
Views
5K
  • · Replies 1 ·
Replies
1
Views
4K