How to choose a good password
Choosing a strong password – here’s a potential method to help you create one from a Senior Consultant at Sophos.
DO's
Your password should:
- Be at least nine characters long (with a maximum length of fourteen characters)
– a longer password is harder to crack, but may be more difficult to remember. - Ideally be a random sequence of letters, numbers and punctuation characters – please avoid using the following symbols as they are known to cause login problems with main University systems: ” £ < : % ) @ and !
- Be a mixture of upper and lower case letters and include at least one number – all Cardiff University systems recognise case sensitivity in passwords.
And it could:
- Be bits of more than one word joined by punctuation (eg riti-lio from bRITIsh LIOns).
- Use the initial letters of a memorable phrase (see below video for more details).
DONT's
What shouldn’t your password be:
- Do not make the password the same as your account name.
- Do not use your surname or any of your forenames as a password.
- Do not use the names of your boy or girlfriend, relative, dog, cat, budgie …
- Do not use your car registration number – even an old one!
- Do not use your address.
- Do not use any word found in a dictionary (nor plurals) even with a numeral on the end.

