A simple list of Dos and Donts to consider when creating new accounts or updating passwords for current accounts you have.
It may sound simple, but mistakes can often be made when in a rush or creating multiple accounts.
This post contains common good practice. Why not get into the habit of creating good passwords, before bad habits set in?
- Use your account name or any data that appears in your record in the password file.
- Use any word or name that appears in any dictionary, reference or list regardless of case changes; especially do not use character strings that appear in password cracking tools’ word lists or bad password lists.
- Phrases and slang with or without white space. Redundant with 2. See below.
- Use any mythological, legendary, religious or fictional character, object, race, place or event. Redundant with 2.
- Use acronyms. Redundant with 2.
- Use alphabetic, numeric or keyboard sequences; many such sequences are included in cracking tools “word” lists. Redundant with 2.
- Titles of books, movies, poems, essays, songs, CDs or musical compositions. Redundant with 2.
- Vary the character sequences obtained from any of the foregoing items by any of the following methods:
- Prepend or append symbols, punctuation marks and / or digits to a word.
- Use words with some or all the letters reversed.
- Use conjugations or plurals of words.
- Use words with the vowels deleted.
- Replace letters with like looking symbols or digits.
- Replace digits with like looking letters or symbols
- Use only the first or the last character in uppercase. Redundant with 2.
- Use only vowels in uppercase. Redundant with 2.
- Use only consonants in uppercase. Redundant with 2.
- Use any personally related information.
- Use anything you can imagine being collected into a list.
- Use a publicly shown example good password.
- Use great vanity license plates. In the future, may be redundant with 2.
- Transliterate words from other languages.
- Repeat any character more than once in a row.
- Use at least 8 characters.
- Include a digit or punctuation.
- Use upper and lower case.
- Choose a phrase or combination of words to make the password easier to remember.
- May be two words separated by a non-letter non-digit.
- May have non printing characters.
- Use different passwords on different machines.
- Change password regularly and don’t reuse passwords or make minor variations (incrementing a digit).
The suggestions overlap as they come from different sources. Most users and some systems will have real difficulty with non printing characters.
Personally related information Most people choose passwords that are easy to remember. One way to make passwords easy to remember is to pick passwords or parts of password that are directly related to oneself. Generally these are considered to be poor password choices.
Below is a list of all the personally related information that I have seen in passwords or in lists of what not to use in passwords. It’s listed in the order in which I think this information is most likely to be used in forming passwords:
- One’s names and initials.
- One’s account name.
- Names of immediate family members.
- Names, breeds or species of pets.
- One’s birthday.
- Family member’s birthdays.
- One’s vehicle make, model, year.
- Hobbies, interests and related words.
- One’s job title.
- Employer’s name.
- Job related words.
- Friend’s names.
- Street numbers or names, city, county, state or zip code for home, work, family or friends.
- Phone numbers for home, work, family or friends.
- Social security numbers for self and immediate family.
- License plate numbers.
- Birthplace including street address.
- University or college name.
- College major.
- High school name.
- Student or employee ID numbers.
- Serial numbers from consumer products.