In general, stick to items known over a period of years. Trying to remember a password including a favorite song, for example, could be difficult if the favorite song changes on a weekly basis. The names of children, a spouse, a pet, or a favorite sports team are easily determined by others and could be used to attempt to compromise the account. The following suggestions include the required combination of letters and numbers, using both upper case and lower case letters to further improve the quality of the password.
Use the initial letters from an easily remembered phrase, interspersed with numbers. For example, IPA85ttfotusoa ("I Pledge Allegiance to the Flag of the United States of America", with a graduation year in the middle).
Use the name or initials of a person (an actor or past teacher, for example) and a date associated with that person (birthday, anniversary, etc.).
Combine three or more digits of a telephone number or street address with the initials of the individual associated with that number or address -- only if it is NOT published. On this note, it is also not a good idea to use numbers of a license plate, since anyone could make note of the plate number and try it as a possible password.
Choosing password generating schemes such as those above is no more difficult and takes no more time than choosing a new password. In fact, once the scheme is nailed down, choosing new passwords from time to time is much easier. Note that the network server will not allow any new password that differs only by the addition of a trailing character.
Password creation rules:
- CANNOT contain three or more consecutive characters from your full account name or username (for example, Joe Smith or smithj can not include joe, oes, esm, smi, mit, ith, or thj in his password)
- MUST be 8 to 15 characters
- CANNOT be a password that was used previously
- Contain characters from three of the following four categories:
- uppercase English characters (A through Z)
- lowercase English characters (a through z)
- numerals (0 through 9)
- Non-alphabetic characters (for example, !, $, #, %)
- CANNOT contain spaces
- CANNOT be changed again for a 24-hour period