Your best defense against hackers is a long, random passphrase. A strong passphrase is as long as possible. Always use at least four words, totaling 15 or more characters, in your passphrase. The longer the passphrase, the more difficult it is to attack with a "brute-force" search (a computer testing thousands of combinations against yours every second).
Characteristics of a Strong Passphrase
- Does not contain your name, NetID, or any personal information
- Is made up of four or more random, unrelated words
- Is memorable to you (does not have to be written down)
- Is a minimum of 15 characters long
- Can be typed quickly (deters others from learning your passphrase as you type it)
DO Use Random, Unrelated Words
A particularly effective technique is to string together several words that have no connection to each other or to you, such as:
- lamp Orbit flannel 7 cactus thunder. - Five unrelated words plus a number and punctuation
- panoramic nectar precut handclap - Four random words with no personal meaning
- copper6 wandering pretzel outlet - A mix of random words and a number
DO NOT Use Personal Information
A weak passphrase is one that:
- Uses personal information, such as your name, a friend's name, a pet's name, your phone number, social security number, birth date, or address
- Uses words with an obvious connection to each other, such as a quote, song lyric, or common phrase
- Uses any single word in the dictionary, whether spelled frontwards or backwards
- Is easy to spot while you're typing it, e.g., 12345, qwerty (top line of keyboard), or nnnnnn
Keep Passwords Secret
A common way for hackers to trick people into giving away their passphrases and other personal information is through a scam called "phishing." Phishing is the practice of sending millions of bogus emails that appear to come from popular websites like eBay or Amazon. The emails look so official that many people will respond to requests for their login name and passphrase.
The University, Microsoft, eBay, Amazon, PayPal, or any other reputable company never asks for your passphrase through email. If you receive a request for your passphrase, social security number, or other sensitive information via email, notify the University at abuse@unr.edu if University related or notify the company immediately by phone or through their website if from a reputable company.
Have questions or need additional assistance?
Get Help