TechRepublic : A ZDNet Tech Community

Help users create complex passwords that are easy to remember

Tags: Michael Mullins CCNA, MCP, password, password policy, Security Solutions Newsletter

  • Save
  • Print
  • Recommend
  • 13

Takeaway: Passwords are only as good as the policy that enforces their use. That's why it's imperative that organizations employ a written password policy—and that they take steps to enforce it. In this edition of Security Solutions, Mike Mullins discusses how to create an effective password policy, and he offers a trick to share with users for creating strong, complex passwords.

While most end users understand the importance of using passwords to secure corporate systems and data, they don't always know how to create a strong password. That's why it's just as important to create a strong password policy in your organization. Remember: Passwords are only as good as the policy that enforces their use.

By default, Windows disables the password filter in the Default Domain Group Policy Object (GPO) and in the local security policy of workstations and servers. That's one more reason why it's imperative that organizations employ a written password policy—and that they take steps to enforce it.

For example, if your company's password policy only requires a minimum of six characters and doesn't require complexity (i.e., a combination of uppercase and lowercase characters, digits, and/or nonalphanumeric characters), then you've got a pretty weak policy. That means most users will use passwords that are easy to crack through either brute force or social engineering.

How do you make sure your users create strong passwords that hackers can't easily guess? Your first step is to enable the password filter in the GPO or on local stand-alone workstations and servers. To find the password filter, go to Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy in the Group Policy MMC in the Default Domain policy. After enabling the password filter, you can start creating an effective password policy for your users.

Craft a strong password policy

Let's look at some best practices for effective password policies. Most organizations require users' passwords to have a minimum of eight characters. They also specify that passwords must meet at least three of the four complexity requirements—uppercase letters, lowercase letters, numbers, and nonalphanumeric characters.

Organizations should also configure the password history to remember the last 24 passwords, which is the maximum setting. This virtually ensures that users won't reuse passwords.

In addition, you should set the minimum and maximum age of the password to an appropriate level. I recommend setting a maximum age of 180 days and a minimum age of 90 days. This prevent users from cycling through passwords until they can return to the one they want.

Put your policy in action—and enforce it

It's smart to establish a good password policy in your organization, but it's even more important to actually enforce it. A strong policy that no one has to follow doesn't add any more security than no policy at all.

In addition, it's important to remember that a good password policy doesn't work if users have to write down their password because it's so complex. That only transfers the security risk instead of mitigating it.

So how can you make sure users' passwords are complicated enough to deter hackers and easier enough to remember? One of my colleagues offers the following trick for creating complex passwords that meet complexity requirements while still being possible to remember.

Step 1: Come up with a base word
Pick the name of a pet or any common thing that's easy to remember. For example, say you once lived in Louisville. You can use that to establish the base of your password and satisfy the required criteria for a strong password.

Remember: You need at least one capital letter and either a number or special character. So, using Louisville as your base word, you can substitute an ! or 1 for i and replace the s with $—e.g., Lou1$ville or L0u!$ville.

Step 2: Add more characters to the base word
Pick any four characters to add to the base word.

Step 3: Store your password without worry
Now, write down the added four characters, along with a clue for the base word. Using our previous example, you would write down city1xyza, where city1 signifies Louisville with a 1 and $ and xyza represents the four additional characters.

So, even written down, this password reference would serve as a reminder of your complete password while revealing nothing to any roaming eyes. (Keep in mind that this example is a 14-character password. While that may be longer than the actual requirement, it may be easier to remember.)

Final thoughts

Password policies only work if you turn them on. Make sure you've trained your users on how to create complex passwords that they can remember without leaving a paper trail that prying eyes can easily follow.

Miss a column?

Check out the Security Solutions Archive, and catch up on the most recent editions of Mike Mullins' column.

Worried about security issues? Who isn't? Automatically sign up for our free Security Solutions newsletter, delivered each Friday, and get hands-on advice for locking down your systems.

Mike Mullins has served as an assistant network administrator and a network security administrator for the U.S. Secret Service and the Defense Information Systems Agency. He is currently the director of operations for the Southern Theater Network Operations and Security Center.

  • Save
  • Print
  • Recommend
  • 13

Print/View all Posts Comments on this article

All well and good, but it's down to the user... Dominick-Murphy | 01/20/06
totally agree on critical point is on user th7711 | 01/20/06
Excellent Discussion! Mike Mullins | 01/20/06
Password curtis2164 | 02/11/06
User Security ame4c | 01/20/06
Password Security Policy is Mandatory rasilon | 01/23/06
Booktitles , people, movies you loved, butcher them up jdh9@... | 01/20/06
Fine, as long as security isn't needed... Starderup | 01/20/06
fingerprint scannert Babac | 01/20/06
Biometrics... fore_thought@... | 01/30/06
eh Becca Alice | 06/01/07
its not just cycling through w2ktechman | 01/20/06
How secure are key patterns? john@... | 01/23/06
risk assessment Babac | 01/23/06
Have a quiet word about bad passwords Eldane | 01/30/06
Clever... and no doubt effective kate@... | 01/19/07
What I do...... jedurham36@... | 02/02/06
stupid users can blow up the best security plan bg6638@... | 02/02/06
Arrogance! darinhamer | 02/02/06
Arrogance I think not! bg6638@... | 02/02/06
A phrase is easier to remember, more secure bfelts | 02/02/06
null Tony F | 02/02/06
Security Not Important to Users alfmars | 02/03/06
User education about consequences is huge Becca Alice | 06/01/07
Four related group policy settings RoadWarrior | 01/19/07
Strong passwords easy to remember dvukovic@... | 01/20/06
Strong Passwords jdpadro@... | 01/20/06
I pick a phrase TonytheTiger | 01/20/06
thanks crawdaddy45 | 01/20/06
Pick something on you desk tomhirtler@... | 01/20/06
Sounds good, but.... rasilon | 01/23/06
Yet another method: Keyboard Patterns melo103@... | 01/30/06
Good Points, But KWKrueger@... | 01/19/07
An even better solution martin.littmann@... | 01/20/06
and every bad guy knows this already catcher@... | 01/20/06
Is it just me ? It's all so simple. MerchantBanker | 01/21/06
Got it in 2 Laughing Jack | 01/30/06
Why have users at all? darinhamer | 01/30/06
Yes, Internal Customers omoore@... | 01/30/06
Open your mind to the real world... Dominick-Murphy | 02/02/06
IT is not the "Real World" Wayne M. | 02/02/06
Well said Wayne ... MerchantBanker | 02/02/06
Oops ... typo time ! MerchantBanker | 02/02/06
Or perhaps IT needs to open its' mind shardeth | 01/19/07
Good posts - my 2 cents MarioAt@... | 02/01/07
Not really... rasilon | 01/23/06
Minimum 90 days way too long gstump@... | 01/20/06
Wow - you are brutal catcher@... | 01/20/06
MINIMUM password age tomhirtler@... | 01/20/06
This won't always work AlanGeek | 01/20/06
Everything has a weak point catcher@... | 01/20/06
au contraire NI70 | 02/01/06
But will they come?? rasilon | 01/23/06
compromise should be reported gggies | 01/21/06
passphrase RLCF | 01/20/06
Bible Verse password builder Dave Flick | 01/20/06
Another way to remember passwords cornejo.alvaro@... | 01/20/06
Sing your way into passwords neildsouza | 01/21/06
Dictionary Terms IAmASensFan | 01/30/06
Re: Dictionary Terms ame4c | 02/02/06
Too Many: Accounts, Passwords, Rules, Changes Wayne M. | 01/31/06
A lot of good suggestions glgruver | 02/02/06
Very good tips and tricks siddhpura@... | 06/20/06
Good secure password pealjay@... | 08/09/06
A little morbid... tom.geraghty@... | 01/19/07
But better than her age at birth NickNielsen | 01/19/07
Use your Native Language shahid.ghani@... | 01/19/07
Sometimes management don't help.. tom.geraghty@... | 01/19/07
Unreal... markinct | 01/19/07
Disgusting hcetrepus | 01/19/07
Legal Yes danshea@... | 01/19/07
Significant difference... tom.geraghty@... | 01/22/07
This may be a stupid question, but... Becca Alice | 06/01/07
Research, people! gshollingsworth | 01/19/07
Phone Pad and Corresponding Letters Your Mom 2.0 | 01/19/07
People are Still the Problem jpopinski3@... | 01/20/07
RE: Help users create complex passwords that are easy to remember fat_fat@... | 09/21/07

What do you think?

White Papers, Webcasts, and Downloads

Article Categories

Security
Security Solutions, IT Locksmith
Networking and Communications
E-mail Administration NetNote, Cisco Routers and Switches
CIO and IT Management
Project Management, CIO Issues, Strategies that Scale
Desktops, Laptops & OS
Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
Data Management
Oracle, SQL Server
Servers
Windows NT, Linux NetNote, Windows Server 2003
Career Development
Geek Trivia
Software/Web Development
Web Development Zone, Visual Basic, .NET

SmartPlanet

Click Here