Username and Password Security Guide
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report to Moderator
- Plusnet Community
- :
- Library
- :
- Username and Password Security Guide
Username and Password Security Guide
There are things you can do to make your username and passwords more secure. This guide gives you tips.
Username Security
Password Security
Changing Your Plusnet Passwords
Changing Your Password Settings
- Configuring password policies in Windows
- Enforce password history
- Minimum password age
- Minimum password length
- Password must meet complexity requirements
- Store password using reverse encryption
1. About username security
E.g. A broadband username looks like:
- username@plusdsl.net
- username@f9.co.uk
- username@freeonline.net
2. Ways you can find out your password and broadband username
- Log into the Member Centre.
- Under My Account click on Connection Settings.
- Click on Connection Details.
- Find the Login name row in the table (3rd row down) – this is your broadband connection username, e.g. username@plusdsl.net
Look in your modem/router's connection settings. When you set up your broadband connection these details will have been automatically stored, although for security reasons your password will be disguised (e.g. ********).
Password Security
1. About password security
2.Choosing a secure password
The best kinds of passwords are those which can't be easily guessed by intruders. The trick is to try to create a password which you find easy enough to remember, but random enough to make a difficult barrier to get past.
Here's some help:
- Your password should be - between 8 and 16 characters in length and ideally include at least one number.
- Don't create an obvious password - but make it easy to pronounce (this way you'll remember it more easily). This will help reduce the threat of your password being found by 'dictionary' based tools which some attackers use.
- Characters which can be used
- Upper case and lower case letters (a-z and A-Z)
- Numbers (0-9)
- Special characters (!##%&()*+,-./:;<=>?@[]^{|}~. )
- Characters which can't be used
- Single quote - ‘
- Double quote - “
- Backslash - \
- Pound sign - £
- Space
- Passwords can begin and end with a letter, number or a special character
- Create a passphrase - why not take the first letter of each word from a line in your favourite song, or book and put them together to make a word?.
- Most importantly - always use different passwords for different programs and services. This reduces the threat of anyone using the same password to log into all of your services/accounts.
Important! If you change your Plusnet password you will need to update your hardware settings to use your new password. Check the instructions that came with your hardware for how to do this. If you got your hardware from Plusnet see our Broadband Hardware Guides.
3. Password security dos and don'ts
- DO - Use a password if you share a computer with other users. If you don't you are risking other people having access to your personal information, deleting files or even using your account to pretend to be you online.
- DO - Have different passwords for different things - don't use the same password for every application or service.
- DON'T - Write your password down - if you can try and memorise it. If you can't remember your password and do have to write it down, try and disguise it, leaving it in a secure place.
- DON'T - Choose an obvious password - e.g. your name, or a family member's or pet's name, your date of birth, telephone number, the current month or 'password'. It's very easy for someone to guess all of these.
- DON'T - Keep the same passwords - change them every once in a while and don't re-use a password for at least a year. Change passwords at work - every 2 months and change passwords at home - every 6 months.
1. Where to change your passwords
Service | When is the password set? | How do I change the password? |
---|---|---|
Broadband access Dialup access Broadband Phone Usenet Default mailbox Portal login Homepages login Homepages Webstats | During signup. You enter a password of your choice | Change your account password using the Change Password tool |
Additional mailboxes | When mailboxes are setup | At the Member Centre in the Email Settings section under Manage My Mail |
CCGI | Uses your current password when CCGI is activated | To change your password, log into cshell.plus.net using either telnet or ssh and run the passwd command. Note: If you need to change your CCGI password, you will only be allowed to use a very strong password when running the passwd command. (e.g. At least 6 characters and the more characters, the stronger the password) |
FrontPage | Uses your current password when FrontPage is activated | This can be changed using FrontPage itself by following these instructions:
|
My SQL | A random password is generated | Raise a Question through the Help Assistant requesting a MySQL password reset. This will generate you a new password which will be emailed to you |
Webstats (CCGI, FrontPage) | Uses current password when component is activated | Raise a Question through the Help Assistant, we will reset your webstats password to match your main account password |
1. Configuring password policies in Windows
Changing your computer's password settings means that a particular password can't just be re-used over and over again.
Important: We suggest you only configure your Windows password policies if you are an experienced user, confident with changing system settings. If you are unsure, don't make any changes.
In Windows XP:
- Click Start.
- Click Control Panel.
- Click Performance and Maintenance.
- Click Administrative Tools.
- Click Local Security Policy.
- Click the plus-sign (+) in the left pane to open Account Policies.
- Click Password Policy.
2. Enforce password history
This lets you set the number of days that Windows will remember passwords before they expire.
- Double-click Enforce password history.
- On the screen that appears choose any number between 0 to 24 from the drop-down. This is the amount of passwords that Windows will remember. Setting this at 0 means that no passwords are saved.
- Double-click on Maximum password age.
- On the screen that appears choose any number between 0 to 42 days from the drop-down list. Setting this at 0 means that passwords will never expire. (We suggest that you set this to 30 days or less - so that passwords are changed on a monthly basis).
3. Minimum password age
This lets you set the number of days which must pass before a password can be changed again.
- Double-click Minimum password age.
- On the screen that appears choose any number between 0 to 998 days from the drop-down list. (We suggest that you set this to at least 3 days if you've set the Maximum Password Age (above). The Minimum Password Age can't be higher than the Maximum Password Age. If the Maximum Password Age is set to 0 the Minimum Password Age can be set from anything from 0 to 998 days.
4. Minimum password length
This lets you set the minimum number of characters that a password can contain.
- Double-click Minimum password length.
- On the screen that appears choose any number from 0 to 14 in the drop-down list.
5. Password must meet complexity requirements
This lets you set the password length and type of characters that a password can be made up of.
- Double-click on Password must meet complexity requirements.
- On the screen that appears choose Enable.
- You will then be given a number of password rules:
- Password must not contain significant portions of the user's account name or full name.
- Password must be at least 5 characters in length. (We suggest setting this to at least 8 characters to make passwords secure).
6. Store password using reverse encryption
This lets you keep a check on all the passwords used on a computer.
- Double-click on Store password using reverse encryption for all users in the domain policy.
- On the screen that appears choose Enabled.
Important: Password storing makes your password security less secure. Enabling this is basically like writing every password used on a computer in a text file, meaning these can be checked very easily.
You should ONLY turn this on unless you really need to log all the passwords used on a computer.