Why passwords are the #1 target
Attackers rarely "hack" their way in; they log in. Billions of stolen passwords from past breaches circulate freely, and automated tools try them against every service you use. If you reuse a password anywhere, one breached website can unlock your email, your bank, and your work accounts.
The two rules that matter most: use a different password for every account, and turn on multi-factor authentication (MFA) everywhere it's offered, starting with your email. Do those two things and you're ahead of 90% of the internet.
Build passwords that hold up
- Length beats complexity. "Tr0ub4dor!" falls in hours; "correct-horse-battery-staple" takes centuries. Aim for 16+ characters; a few random words works great.
- Random beats memorable. Anything based on your name, pets, birthdays, or teams can be researched from your social media in minutes.
- Never reuse. Not even "the same but with a 2 on the end." Cracking tools try those variations automatically.
- Don't rotate on a schedule. Modern guidance (including NIST's) says forced periodic changes lead to weaker, predictable passwords. Change a password when there's a reason, like a breach, a suspicious login, or a departing employee.
Get a password manager
Nobody can remember 80 unique strong passwords, and you shouldn't try. A password manager generates, stores, and fills them for you, locked behind one strong master passphrase. Browser-built-in managers are fine; dedicated apps add sharing and breach alerts for teams.
- Make your master passphrase long, unique, and memorable; it's now the one password you actually memorize.
- Protect the manager itself with MFA.
- Bonus phishing defense: a password manager only auto-fills on the real website. If it refuses to fill, look hard at the address bar.
Multi-factor authentication (MFA)
MFA adds a second proof of identity: something you have (your phone, a security key) on top of something you know. Even if your password leaks, the attacker hits a wall.
- Best: a hardware security key or passkey, immune to phishing.
- Great: an authenticator app (time-based codes or push approval).
- Better than nothing: SMS codes. Vulnerable to SIM-swapping, but still stops the vast majority of attacks.
Two MFA scams to know: ① Push fatigue: an attacker with your password triggers approval prompts until you tap "Approve" just to make them stop. Never approve a login you didn't start. ② Code harvesting: someone calls "from support" and asks you to read them the code you were just texted. No legitimate company ever asks for that code. Ever.
Do this today
- Turn on MFA for your email account; it's the master key to everything else (password resets land there).
- Turn on MFA for banking, work logins, and your password manager.
- Install a password manager and move your five most important accounts into it with fresh, unique passwords.
- Check your email address at a breach-notification service like haveibeenpwned.com and change any exposed passwords.