Skip to main content
Pepperdine | Community

Passwords: Everything You Need to Know

Overview

Passwords are one of the cornerstones of keeping your information secure. Per the University's Computer and Network Responsible Usage Policy, passwords must conform to IT’s published complexity and length requirements, and must not be shared with any other person, used in non-University accounts, or otherwise disclosed.

When in doubt, follow these four guidelines:

Icon of a weight-lifting dumbbell.

Keep It Strong

Use a unique, strong password with 15+ characters for each website, preferably a passphrase.

Icon of a folder with a shield icon.

Protect It with a Password Manager

Use a recommended password manager to generate and store your passwords. They're secure, and some are free!

Icon of a recycle symbol with a slash through it.

Don't Reuse It

Do NOT reuse your Pepperdine NetworkID password on any site that doesn't use Pepperdine single sign-on. 

Icon of a share arrow with a slash through it.

Don't Share It

Do NOT share your Pepperdine NetworkID password with anyone or any technology other than a supported password manager.

Keep Your Password Secure

The Computer and Network Responsible Usage Policy outlines three absolute rules to follow to keep your password secure:

  1. Don't Reuse. Do not use your University passwords, or anything like them, on other systems.
  2. Don't Share. Do not share your password with anyone (including your supervisor, co-workers, friends, or family) or any tool, service, or technology (including AI tools and third-party apps, with the exception of an approved password manager).
  3. Report and Change: Change your password immediately if you suspect it has been compromised or disclosed. Report any information breach, including a compromised account or password, immediately to the Information Security Office.

Use a Password Manager

If you have many different passwords to remember, consider a password manager that uses real encryption. A password manager is software that stores all your passwords under a single password. The Information Security Office has evaluated several free products with proper encryption and recommends them, but they are not supported by Pepperdine IT.

Write the Password Down (Temporarily and Securely)

It is best to memorize your password, but you may write your password down while you're learning it. This may seem counter to security, but it is sound security advice, and this is the proper way to do it:

  • Lock it away in a desk or file where you have the key.
  • Do not label it or otherwise indicate it is your password.
  • Destroy it when you no longer need it.

Creativity and fun help you make a strong password that you can more easily remember. Before committing to a password, make sure it's one that isn't too hard to type!

Use a Passphrase

Rather than a password, use a passphrase. Essentially, convert a sentence, quote, or phrase that is meaningful to you but not something others can easily guess. A passphrase is the best password available because it is longer and can be made very hard to guess when combined with capitalization, numbers, and symbols. In addition, it may be easier for touch typists to enter a passphrase rather than a password. Note: A space (" ") counts as a valid character in a password.

One method for creating a passphrase:

  1. Choose a phrase you can remember, but not one you say or write frequently, and not one of the following examples. For instance:
    • All for one, and one for all!
    • Buy low, sell high.
  2. Add or change characters so that it's not a verbatim proverb (and add capitalization, numbers, and/or special characters): Examples:
    • all for One 1 for all
    • Buy low & sell 2 high.

Do NOT use any of the above examples as your passphrase! Keep it secret to keep it safe.

Common Mistakes

Not all passwords that meet our technical requirements are strong! Generally speaking, you can consider that if a word is in the dictionary, it's in the hacker's toolbox as well. You can also assume that anyone targeting you will use any publicly available information about you, be it words, names, or numbers, to hack your password. Have a look at the 200 Most Common Passwords according to Nord Security. Never use these passwords because hackers and opportunists will try them first!

Passwords to Avoid

  • Avoid passwords based on well-known passwords or their derivatives. The following examples have been found on dozens to thousands of accounts at Pepperdine — don't use anything like them!
    • Waves123
    • Password!
    • Autumn09, Spring2012 and similar
  • Avoid guessable passwords based on family member names, birthdates, pet names, school names, and home addresses.

Create Stronger Passwords

Passwords are made stronger by increasing length, altering capitalization, and using special characters.

  • Long Passwords: When it comes to strong passwords, longer is better. Therefore, a passphrase is generally stronger than a password. Even adding a few characters makes a big difference. A 12-character password is potentially 30 million times stronger than an 8-character one.
  • Mixed Case and Numbers: Use a combination of uppercase and lowercase letters, along with numerals. When using a passphrase, convert some words to numbers and mix the case of the words. For example (don't use this one!):
    • @ fareWELL2-aRmS!
  • Special Characters: Use special characters in your password. Adding special characters expands the "password alphabet" and makes your password even stronger. The term "special characters" as used by IT includes the following:
    • ! @ # $ % & ^ ~ _ * - = + ` ' " , . ; : ? | / \ ( ) [ ] { } < > space

 

Technical Requirements

Information Technology implements technical controls to enforce strong password requirements. Pepperdine NetworkID passwords (for Pepperdine user accounts) have different requirements than PGP system passwords (for encrypted devices). 

The University requires every holder of a Pepperdine NetworkID to create a unique network password for their account, in accordance with the standards set by Information Technology (see the Computer and Network Responsible Usage Policy). The current IT standards for password composition are that every password meets the following complexity criteria as to length, characters, and source:

  • Length: A password must be at least 15 characters.
  • Characters: A password must contain the following four types of characters:
    • Uppercase letter (e.g., ABC)
    • Lowercase letter (e.g., abc)
    • Numeral (e.g., 123)
    • Punctuation, symbol, or space (e.g., "! @ # $ % & ^ ~ _ * - = + ` ' " , . ; : ? | / \ ( ) [ ] { } < >")
  • Source: Passwords must NOT:
    • Include your Network ID name
    • Match one of your five previous passwords

IT password complexity standards were improved in August 2009 and later expanded in October 2021.

For persons storing RESTRICTED information on their computers, the Information Classification and Protection Policy requires storage encryption (hard drive, disk, etc.). IT supports enterprise PGP (Pretty Good Privacy) Whole Disk Encryption (WDE) for this policy-mandated requirement.

The technical requirements for a PGP WDE passphrase are:

  • Length: 20 or more characters.
  • Complexity: Meets the PGP-calculated complexity threshold of 60% or more. (The PGP software will calculate this complexity percentage for you and give real-time feedback as you type.)
  • Composition: Must not resemble or be based on your Network ID password.

Learn more about Whole Disk Encryption.

Password Expiration

Passwords for your Pepperdine NetworkID will automatically expire four years after your last password change. A user may change their NetworkID password at any time and does not need to wait for the automatic expiration. If a user believes their password may have been compromised, they should immediately change their password at myid.pepperdine.edu and report the incident to the University's Information Security Office (310.506.4040) or Tech Central (310.506.4357).

Account Lockout

If you (or one of your mobile devices) attempt to log in to a Pepperdine service too many times with an incorrect password, your account will be automatically locked. If this happens, you can use MyID to reset your password, or call IT Tech Central at 310.506.4357 for technical support.

Protect Your Mobile Device or Tablet

Faculty and staff are required to set a 15-minute timeout and a PIN (Personal Identification Number) on any electronic device used to access Confidential University information. This includes setting a timeout and a PIN on mobile devices that have access to University email.

By University policy, access to Confidential information, such as email or student/business records, must be secured by passwords that meet current IT standards. The current minimum IT standard for mobiles is a PIN (6-digit numeric code). A person with physical access to your phone can decrypt PIN-protected contents in minutes; therefore, a password or passphrase is much better security. However, a PIN is effective in hindering someone who is casually accessing a lost/stolen phone from browsing the information on it. Biometric authentication, such as fingerprint or face scans, is acceptable once you set a PIN and screen timeout (auto-lock). It is recommended that you turn on your device's feature that allows you to find it or wipe it if lost.

Have a look at the Top 10 Phone PINs. Never use these PINs, because hackers and opportunists will try them first.

The Limits of 6-Digit PINs

Never use a 4-Digit PIN. While even 6-Digit PINs are possible to guess by hand, and certain to be guessed by a machine, here are some general guidelines when using a 6-Digit PIN:

  • Don't use 6 consecutive or 6 of the same digits (e.g., don't use 111111 or 123456).
  • Turn on the feature that locks or wipes your device after 10 wrong guesses.

Consider an Alphanumeric Passcode for Tablets and Mobiles

For extra security, use an alphanumeric passcode:

  • Turn off the "simple passcode" option and enable the alphanumeric passcode.
  • Combine digits and letters for your device passcode.

 

Avoid Pepperdine Account Lockouts!

If you have saved your Pepperdine NetworkID password in mobile devices or email apps that periodically log in with that password, you may be locked out of your Pepperdine account if you forget to update the password after changing or resetting it! Be sure to update your password on any mobile device app, such as:

  • Mobile device email app
  • Computer email app (e.g., Outlook, Thunderbird) that uses IMAP to send/receive messages
  • Calendar apps
  • Password manager (if a password manager auto-populates your password in a web browser)

Note: Use official Google apps or Gmail to minimize account lockouts!

Change or Reset Your Password with MyID

Whether you are setting your password for the first time or you need to change your password, use MyID to manage your Pepperdine NetworkID password.

 

Third-Party Websites Not Using Pepperdine Single Sign-on

When Creating an Account or Logging In

If your school or department licenses or provides a third-party web application, but it does not participate in Pepperdine CAS/SSO login, you must:

  • Create a separate password for the third-party application (do not reuse your Pepperdine NetworkID password on a third-party website).

Information for Managers or Owners of Third-Party Applications

If you have licensed a third-party application for your school or department that will be used by students, faculty, and/or staff, you must:

  1. Double-check with the vendor whether they support CAS or SAML integration, and license the product accordingly.
  2. If the vendor does not support CAS or SAML, configure the application to require strong passwords. Match the Password Technical Requirements above.
  3. If the vendor does not support CAS or SAML, you must inform your users that they must not reuse their Pepperdine NetworkID password on this third-party service. They must create a new and unique password that is not a derivative of their Pepperdine NetworkID password.

If you have any questions about this, please contact the Information Security Office and speak to a security operations analyst.

 

Why All of This Matters

If you use your Pepperdine University email address to create an account on a third-party website, and that outside website is hacked and the passwords exposed, you do not want to hand the hackers access to your official Pepperdine University account (or any of your other accounts!). Your Pepperdine account includes access to services that can expose your home address, your financial information (direct deposit, financial aid, retirement), grades, and more! Never reuse your Pepperdine password on any other website to protect your own information and to protect the University from cybercriminals.

If you have bad password habits, it's time to adopt healthy ones by:

 

Need Tech Support?

Call Tech Central: 310.506.4357 (HELP)
Hours: 24 hours a day, 7 days a week, 365 days a year

Have A Suggestion for IT?


Click to share your suggestion, anonymously if preferred, to improve Pepperdine IT.