» For students  » IT Ressources at IHA  » Security & Safety  » Password 

Password

 

Why is a password so important?

Password's are important because you can protect your data (documents) against abuse by using a password.

 

Why is a password so personal/confidential?

The reason your password needs to be personal/confidential is to prevent abuse by others. This could e.g. be sending emails in your name. Your password needs to be just as secret as e.g. your pin-code for your credit card.

 

What is a strong password?

A strong password consist of both capitalized letters, non-capitalized letters, numbers and symbols. It can be difficult to remmember a password like "I!s8Cw#pt", but it can make it easier to remmember if you use the initial letters of a foolish sentence: "I ! saw 8 Chessplayers with check pattern today". Here "check" is exchanged with "#". Numbers and symbols should not only be the first and last character, but should also be in the middle of the password.

 

What is the password policy for creating new passwords?

Here at IHA the password policy is that the password needs to be a minimum of 8 characters. A password can consist of capitalized/non-capitalized letters, numbers and/or symbols. You can decide how you build your password.

 

What happens when i log in and are asked to change password?

You are asked to change your password to the network. This password's also used for STADS-Selfservice, CampusNet, mail and other systems at IHA. You only need to change the password in one place.

 

Why do i need to change password every semester?

For security reasons. We here at IHA want to keep a high security level on servers aswell as PC's, and this is the reason that all users have to change their password every 200th day. It's also for security reasons that a password should be a minimum of 8 characters.

 

When i type my password in a browser, is it secure?

This can be both secure and insecure.

 

If the website uses encryption (shown with a small lock in the status bar) then it's by definition only you and the owner of the website that can see your password. If you have been tricked into a false website (so called phishing) and type your password then it has been compromised and might get abused. Because of this, it is important that you read mails and other requests to goto a website and log in with skepticism and criticism.

 

How do i use my password in a more secure manner?

Here's some rules which in short terms describe what to be attentive for.


1. Make sure that the machine you are using is secure - this means that should shouldn't use a machine with public access (libraries, Internet-café's, laborarotys etc., places that are used by alot of people).


2. Make sure that your password isn't visible anywhere in the program you are using. E.g. a browser shows your FTP password in clear text. It's typically shown in the status bar, but can in some cases also be shown in the "location"-line.


3. Be aware that the operating system (e.g. Windows) doesn't save your passwords on the machine. E.g. Windows and IE asks to save your password, so that next time you access the same website, the system will automatically log you in. (By having this enabled others using the same machine can log in to your account).

 

4. If it's a critical password, e.g. net-banking, then make sure the connection is encrypted when you type your password.

29-05-2010/hs