You are on page 1of 2

01

the easiest solution:


01
00101001001010

use a password safe


Password safes save your passphrases or passwords
securely, allowing you to save information on your DIGITAL SELF DEFENSE:
personal computer without giving away private

how to create a
information inadvertently. They can also generate
random passphrases for each of your accounts.

These password safes store all of your passphrases in


a single account, which has a master passphrase you secure passphrase
need to remember. Password safes allow you to use Passphrase - the next generation in passwords!
truly random combinations in all other passphrases,
making them more difficult for malicious users or If you have forgotten your
bots to crack. Two examples of these services are
passphrase or believe it has been
LastPass and Password Gorilla.
compromised, contact the
UBIT Help Center:

when to change your 716-645-3542


Email: ubithelp@buffalo.edu
passphrase
Passphrases should be changed:
• Whenever a malicious program such as a virus
is detected or a machine is compromised
• Whenever leaving a job or starting a new one
get informed
Visit the UBIT website to read the security standards,
• From any default passphrases
access security tools and software, or find out more 010100101001010101
• If they are shared with anyone at any time 00
ways to protect yourself. 11
00
10
01
UB INFORMATION SECURITY OFFICE 01
www.buffalo.edu/ubit/security 01
sec-office@buffalo.edu
(716) 645-6997

Content used with permission from Rochester Institute


of Technology. Updated 8/1/17.
what is a secure how do I create an easy protect your passphrase
passphrase? to remember There are several different ways someone can acquire
your passphrase:
A secure passphrase is the next generation
passphrase?
• Cracking: Password cracking programs are
in passwords. It uses a short phrase instead of designed to guess the most common passphrases
a single word, making it more difficult for someone first. Most current programs can make over one
Here are three simple ways to construct a secure,
else to guess or use. million crack attempts per second.
easy to remember passphrase:
• Malware: Password stealers and keyloggers are
It should be virtually impossible for others to guess, often packaged with viruses and spyware. Always
1. Create a passphrase by taking a short phrase and:
and not contain or be based on personal • Change the capitalization of some of the letters run up-to-date anti-virus.
information. Passphrases should never be written • Replace some of the letters with numerical and • Social Engineering: Never give away your
down or given to anyone else. symbolic substitutions ($ for S, 8 for B) passphrase to anyone, even someone claiming to
• Misspell or abbreviate some words work for a help desk.
(E.g., the phrase “iced tea is great for summer” • Phishing: Universities and companies will never ask
what should I avoid? becomes “!cedTisgr84$umm3R”.) you to confirm your passphrase through email, so
don’t click on links in an email asking you to do so.
There are many ways people try to make their 2. Choose several shorter words and add some Type the URL into a Web browser manually.
passphrases easier to remember. Password cracking numbers in the center, then change the
programs look for the most common passwords first. capitalization and substitute symbols for letters.
(E.g., the phrase “book 451 Bradbury” becomes

why use a secure


Passphrases should NOT: “bO()K451BR^Dbury”.)
• Contain your UBITName
• Be the same as other passphrases you are 3. Choose a memorable quote or phrase and use
currently using (including non-UB services)
• Be a single word, forward or backward, from an
only the first letter from each word. Vary the
capitalization. passphrase?
English or foreign dictionary If someone cracks your passphrase, they can:
Also include numbers and symbols, either as • Obtain your personal information, which can lead
• Contain more than three sequential characters substitutions for letters or as a replacement for a
on a keyboard (ex: qwerty or 1234) to identity theft
full word. (E.g., Wayne Gretzky’s “You will always
• Contain more than two consecutive repeating • Gain access to your email account to read and send
miss 100 percent of the shots that you never take”
characters (bbbb2bbb) email
becomes “ywAM100%ot$tyN+”.)
• Be all numbers such as birth or anniversary • Access MyUB, HUB Student Center or other
dates (ex: 011551) Requirements for passphrases can be found at: services
http://www.buffalo.edu/ubit/password-safety • Access confidential UB information on the
• Be shared with anyone for any reason
university’s network 01
HINT: You can also use a password safe, a program that • Gain information about your registered 101
0
generates and stores random, secure passwords. computers at UB and register their 10
01
10
own on your UB account. 00
1 01
10
00

110 01010100 101001010010101001101001010100101001010010010100101010001010100100101010010101

100
10
www.buffalo.edu/ubit/security

You might also like