SecurePurdue > Best Practices > Password Tips

Password Tips

How To Form and Remember Good Passwords:

Too often, you are expected to create utterly random, complicated passwords with special characters and lots of restrictions.
The net result is ALWAYS a reduction in security because most people will write such a complicated password down in order to remember it.
Goal: Create a password that is easy to remember, but hard for anyone else to guess.
Purdue recommends using the following method for creating a password:

Pseudo-random Passwords:

  1. Pick a phrase that is easy for you to remember, but that no one else will think about attributing to you. For example:
    pass phrase: “My Wife's Birthday Is April Twenty-Fifth Nineteen Sixty Six”
    pass phrase: "Four score and seven years ago our fathers brought…"
    pass phrase: "It was a dark and stormy night."
  2. Use the first letter of each phrase to form an abbreviation. For example:

    m - My
    w - Wife's
    b - Birthday
    i - Is
    a - April
    t - Twenty-
    f - Fifth
    n - Nineteen
    s - Sixty
    s - Six

  3. abbreviated pass phrase: mwbiatfnss
    abbreviated pass phrase: foscanseye (the first 2 letters of each word)
    abbreviated pass phrase: iwadasn
  4. For added security (and usually as a requirement), change one or more of the letters into numerals and/or add punctuation to reach your new password. For example:
    password: mwbi4tfns6 (“a” for “April” becomes “4”, because April is the fourth month; “s” for “six” becomes “6”)
    password: 4scan7ye (“fo” for “four” becomes “4” and “se” becomes “7”)
    password: Iwad&sn! (“i” becomes “I”; “a” for “and” becomes “&”; added “!”)

Any of these passwords would be easy for you to figure out, but would be a nightmare for a password cracker. The idea in this method is not that the password itself is easy to remember but that the process that you go through to arrive at it is so simple that you find yourself re-creating the same password with the process without even thinking about it.

Changing your Pseudo-random password

When the time comes to change passwords, you have a number of options. You can start over from Step 1 to change your pass phrase entirely, or you can keep the same phrase and change the order of the characters you choose from it (taking every second and fourth letter, for example). What matters is that you create very strong passwords that you can easily remember or re-create as needed.
The best place to change your Purdue Career Account password is from the link on the SecurePurdue website.

Bad Passwords

When picking passwords, avoid the following:

For Purdue University password requirements, please see http://www.purdue.edu/securepurdue/bestPractices/passStandards.cfm.