Password choices

Roy Smith roy at phri.UUCP
Sat Jul 9 01:23:05 AEST 1988


	Nobody has yet mentioned the quasi-classic paper "Password Security:
A Case History" by Robert Morris and Ken Thompson.  It's included in the
4.2/4.3 Unix documentation, and probably in most other Unix doc sets.  While
not an authoritative research paper on the subject, it does have some good
suggestions.  They give a short list of commonly used types of passwords,
including anything in the dictionary, possibly spelled in reverse, and valid
license plate numbers in your state.  Obviously, any of the above are bad
choices.

	Personally, I usually use some 6-8 letter word I can remember but
with a deliberate mispelling, often combined with an unusual capitalization
and/or a digit or two thrown in.  Something like "graPHiks88".  Easy enough
to remember, but hard to guess.  If what you're worried about is somebody
watching over your shoulder while you type, the capitals and the digits don't
help much; they just stand out like a sore thumb.  When assigning passwords
for incomming uucp accounts, I just type random patterns on the keyboard.
-- 
Roy Smith, System Administrator
Public Health Research Institute
{allegra,philabs,cmcl2,rutgers}!phri!roy -or- phri!roy at uunet.uu.net
"The connector is the network"



More information about the Comp.unix.questions mailing list