Learn how to create a strong, memorable password that meets NCU's requirements, including a simple passphrase method and habits that keep your account safe.
Why length beats complexity
Every NCU password must be at least 14 characters and include an uppercase letter, a lowercase letter, a number, and a symbol. It can't include your name or username, or reuse an old password.
Length does most of the work. Each added character makes a password far harder to crack, so a long passphrase beats a short, scrambled one, and it's easier to remember. Full rules: Password Complexity Requirements.
Weak
Tr0ub!e#1
Too short, and swaps like 0 for o don't fool cracking tools.
|
Strong
Green-Laptop-Piano-99
21 characters, all four character types, and easy to remember.
|
Build a passphrase
The easiest way to meet every requirement is a passphrase: a few random words joined together. Length makes it strong, and real words make it memorable.
|
1
|
Pick 3–4 unrelated words, such as Orchard, Gravity, and Folder. Avoid song lyrics, quotes, and anything about you that's findable online.
|
|
2
|
Join them with a symbol, like a hyphen or period. That covers the symbol requirement.
|
|
3
|
Capitalize the words and add a number. That covers uppercase and number.
|
Result
Orchard-Gravity-Folder-88
25 characters with all four character types. Make your own; don't copy this one.
Tips for a strong password
What works
- Use a passphrase. Several unrelated words joined with symbols are long, strong, and easier to remember than a short jumble.
- Skip the obvious swaps. Replacing letters with look-alikes (P@ssw0rd) doesn't fool password-cracking tools.
- Use it only for NCU. If another site you use is breached, a reused password puts your NCU account at risk too.
- Use a password manager for your other accounts, so each one can have its own unique password without you memorizing them all.
- Never share it. NCU will never ask for your password. Giving it to anyone, even to let them use NCU Wi-Fi or a service, violates the acceptable use policy.
- Changing it after phishing? Choose a completely new password, not a variation of the stolen one. Attackers try variations first.