Cyber Security Month: Week 2

Password Hygiene

Good password habits are one of the simplest, most effective defences we have and yet they’re often the weakest link due to phishing and other password-related attacks. Often the things that have been around longest have the biggest range of methods available to exploit them. However, passwords are still critical to securing accounts. They help protect personal information, University systems, research data and the services we all rely on every day. 

We recently undertook a controlled security assessment into the University’s password hygiene, using the same tools cyber criminals rely on. This was a controlled, authorised test with appropriate safeguards in place, it wasn’t used to identify or single out individuals, and we never saw anyone’s actual password. 

Here’s how it works: these tools draw on lists of leaked or compromised passwords such as the rockyou list, for example, contains millions of compromised email and password combinations from past breaches. The tool searches for leaked emails, then tries the leaked passwords against those same accounts, sometimes adding a “!” or a digit on the end, just in case. Sound familiar? It’s exactly the pattern most of us fall into when we’re forced to reset a password. 

This is one of the reasons why we ask users not to use their University email for personal accounts such as shopping sites, LinkedIn, etc. If one of those gets breached, your leaked password could be tried against your University account too. 

One thing we specifically tested for was the use of University related terms like “Stirling” or campus building names. These are easy to guess, and several accounts appeared to follow this pattern. As such, here is a reminder that anything closely associated with the University is one of the first things an attacker targeting Stirling accounts specifically would try. 

So we’ve updated our approach

The policy itself is unchanged for now (see our Password Policy). We currently require 12 characters, though this will rise to the best-practice standard of 14 soon (we’ll let you know when). What is changing is that you may start seeing error messages if you try to set a password that’s previously been compromised, or one that relates to University terms. 

In short: your password is one of the barriers between your information and anyone trying to access it without permission. A stronger password helps protect you, the University and the data we are trusted to hold. 

The rules: 

  1. Minimum 12 characters (no maximum). 
  1. Can’t match any password you’ve used before. 
  1. No easily guessed personal info such as your own name, date of birth, a partner’s or child’s name, a pet, your home address, your car, and so on. 
  1. No commonly used words or phrases like “password,” “letmein,” “opensesame.”  
  1. No forced expiry. You won’t need to change your password unless we have reason to believe it’s been compromised. 

Multi-Factor Authentication is already in place on all University accounts, and we’d recommend the Microsoft Authenticator App and a passkey where you can. 

Setting a genuinely strong password 

The National Cyber Security Centre’s advice: use three random words. You can still add numbers or symbols. An example is 3redhousemonkeys27! 

Pick words that mean something to you, not things other people could guess. Your social media gives away more than you’d think. Your child’s name, your favourite team so steer clear of those. And cyber criminals are wise to the obvious substitutions too; “Pa55word!” fools no one. 

Worth remembering: 

  • Never share your password with anyone. 
  • Information Services will never ask for your password. 
  • Use three random words to build it. 
  • Don’t recycle old passwords. 
  • Don’t save passwords in your browser. If your device or browser is compromised, stored credentials are often exactly what malware goes after. Use a password manager instead. 

Leave a Reply

Your email address will not be published. Required fields are marked *