Campus ID News
Card, mobile credential, payment and security
FEATURED
PARTNERS
password 1

Indiana University combatting fraud with robust password policy

Andrew Hudson   ||   Oct 12, 2018  ||   

It's a potentially damaging practice, particularly for universities, with many student and faculty users and valuable assets all protected by passwords.

With this in mind, researchers at Indiana University have examined the practice of password reuse and posited ways to mitigate the risks associated with this insecure practice.

According to research conducted at the university, longer minimum passwords are the most effective way to reduce potential exposure in a third-party data breach, as well as prevent password reuse. The work being conducted by the group of researchers points to a simple way to foil criminals intent on breaking into university data.

Requiring longer and more complicated passwords resulted in a lower likelihood of password reuse, according to research findings from "Factors Influencing Password Reuse: A Case Study." The authors of the paper are Jacob Abbott, an IU Bloomington Ph.D. student; Daniel Calarco, chief of staff for the IU Office of the Vice President for IT and CIO; and L. Jean Camp, professor in the IU Bloomington School of Informatics, Computing and Engineering.

To investigate the impact of policy on password reuse, the study analyzed password policies from 22 different U.S. universities, including IU. The research then extracted sets of emails and passwords from two large data sets that were published online and contained over 1.3 billion email addresses and password combinations. Based on email addresses belonging to university domains, passwords were compiled and compared against a university's official password policy.

The findings were clear: Stringent password rules significantly lower a university's risk of personal data breaches. Some highlights from the report:

  • Passphrase requirements: a 15-character minimum length deterred the vast majority of IU users (99.98%) from reusing passwords or passphrases on other sites.
  • Universities with fewer password requirements had reuse rates potentially as high as 40%.
  • Analysis found that IU performed the best of the 22 examined universities -- and had the most extensive password requirements.

"IU has worked with security and usability faculty to design our password policies, with the result being policies that value people's time while mitigating risk," says L. Jean Camp, professor in the IU Bloomington School of Informatics, Computing and Engineering. "The length and complexity are balanced by the extended period before new passwords must be generated and the use of a longer authentication time window for applications. Indiana University's rollout of two-factor authentication is similarly a model."

In addition to its findings, the researchers offer some recommendations to safeguard university personnel and the general public:

  • Increase the minimum password length beyond 8 characters.
  • Increase maximum password length.
  • Disallow the user's name or username inside passwords.
  • Contemplate multi-factor authentication.
  • Multi-factor authentication is becoming more common and usable. IU, for example, employs Two-Step Login. Multi-factor authentication may be a viable alternative to changing the length and complexity of password policies.
Subscribe to our weekly newsletter

RECENT ARTICLES

Student Financial Experience Report 2026 cover image
Mar 11, 26 / ,

Student payment, mobile, digital ID trends explored in 2026 TouchNet survey

Year after year student expectations continue to rise, and the higher ed institutions that stay ahead of the curve leverage data to strategically improve their student experience. The Student Financial Experience Report, an annual survey commissioned by TouchNet, sheds light on how mobile payments, digital IDs, and other technology affect campus life. The 2026 report […]
Transact + CBORD is now Illumia
Mar 05, 26 /

Transact + CBORD officially becomes Illumia, announces 2026 Distinction Award Winners

Transact + CBORD formerly announced its new name, visual identity, and branding as Illumia at its Momentum annual user conference. According to an announcement about the launch, the company powers payments, access, foodservice, and credentialing at more than 10,000 clients in higher education, healthcare, and senior living institutions. "The Momentum conference is the right place […]
BalanceU meal plan screenshot

New BalanceU meal plan aims to cut costs, open architecture, and free university data

FutureState, a new entrant to the campus credential, dining, and auxiliary service space, announced its new closed-loop, stored value and meal plan offering called BalanceU. “FutureState’s BalanceU is designed to help colleges and universities lower operating costs, eliminate vendor lock-in, and gain real-time financial visibility across campus,” says Christopher Augustine, Co-Founder and Head of Product […]
CIDN logo reversed
The only publication dedicated to the use of campus cards, mobile credentials, identity and security technology in the education market. CampusIDNews – formerly CR80News – has served more than 6,500 subscribers for more than two decades.
Twitter

Great inverview on the Public Key Open Credential (PKOC) standard with ELATEC's Jason Ouellette, Chairman of the Board for the @PSIAlliance.

Attn: friends in the biometrics space. Nominations close Friday for the annual Women in Biometrics Awards. Take five minutes to recognize a colleague or even yourself. http://WomenInBiometrics.com

Load More...
Contact
CampusIDNews is published by AVISIAN Publishing
315 E. Georgia St.
Tallahassee, FL 32301
www.AVISIAN.com[email protected]
Use our contact form to submit tips, corrections, or questions to our team.
©2026 CampusIDNews. All rights reserved.