The Medical
University of South Carolina   About MUSC  ·  Education  ·  Medical Center  ·  Research  ·  Library   

Search


Support Desk, 792-9700
   helpdesk@musc.edu

   Getting Help
   Training
   Account Forms
   Circuit Requests

   Policies
   Description of Fees
   Software Licensing Info
   Software Downloads

   Computer Connection
   Network Systems
   Project Office (PMO)
   Univ Communications

   E-mail
   Google Search Appliance
   Macintosh E-mail
   Modular Messaging
   Homeroom
   LYNX
   NetID
   LDAP Developments
   Single Sign-on
   Oacis
   Off-Campus Access
   Web Publishing

   About IS
   Info Services Home
   OCIO Home
   More IT Groups
   MUSC Home

   Webmaster

   Disclaimer









Selecting Good Passwords

Rationale
What Not to Use
What to Use
Ideas for Choosing Secure and Easy to Remember Passwords
Change your NetID password

Rationale

When choosing a password, the object of the game is to make it as difficult as possible for a cracker to make educated guesses about what you've chosen. This leaves him no alternative but a time-consuming brute force search, trying every possible combination of the 95 ASCII characters (letters, numbers, and punctuation marks) which can be used to construct a legal password. Modern desktop hardware and cracking software can perform on the order of 100,000 password comparisons per second. At this rate, a cracker would need about 1,000 years, on average, to guess a password of 8 characters, if the characters were randomly selected.

Anyone, however, can use readily available desktop hardware and software to guess a poorly chosen password in minutes. How? By using software tools which "understand" how people typically select passwords. For example, because we find it very difficult to remember truly random strings of characters, we might select a password based on an actual word in our first or second language, perhaps adding a digit or two to the end. Or we might pick a favorite word, or someone's name, and spell it backwards. Unfortunately, behaviors like these are highly predictable, and thus the passwords we tend to pick can often be guessed in minutes by password cracking software.

Choosing a good password then, comes down to avoiding the kinds of character string patterns a cracker's software will be looking for, while still coming up with something that you can remember without having to write it down. The following guidelines are meant to help you pick a password which you can remember, but which no one else can predict.

What Not to Use

What to Use

Some Ideas for Choosing Secure and Easy to Remember Passwords

Caveat: Do not use any of these sample passwords as your own!

Adapted from

Improving the security of your UNIX System
National Institutes of Health
ITSTD-721-FR-90-21