Or, just have a half-decent password management tool which keeps an encrypted file of your passwords on your phone, and remember just one password.
Schneier may say it's ok, but to me it seems stupidly insecure, especially when you consider that we're talking about a student's university network password, and that there'll be identification in that student's wallet that allows the thief to make use of the password immediately.
Comments
Apart from requiring exactly 8 characters, the other constraints will genuinely increase security.
Except, of course, that half the students will end up carrying their password on a piece of paper in their wallet.
There is nothing wrong with carrying your password around on a piece of paper in your wallet. This is the Bruce-Schneier-approved method.
http://www.schneier.com/blog/archives/2005/06/write_down_you...
Or, just have a half-decent password management tool which keeps an encrypted file of your passwords on your phone, and remember just one password.
Schneier may say it's ok, but to me it seems stupidly insecure, especially when you consider that we're talking about a student's university network password, and that there'll be identification in that student's wallet that allows the thief to make use of the password immediately.
My biggest issue with it, and other constraints like this though is that it just feels rather contrived.
That and it took far too long to some up with a password passing the description...