Most accounts are not broken into by someone guessing. They are broken into because a password was stolen from one website and then tried on all the others. If you use the same password in more than one place, a break-in at a shop you used once can open your email.
Two habits stop nearly all of this. Neither asks you to remember more.
Habit one: a different password everywhere, kept in a password manager
A password manager is an app that creates a long random password for each account, remembers it, and fills it in for you. You remember a single strong password, the one that opens the manager.
There are good options at every price, including the ones built into Apple devices, Google Chrome and Microsoft Edge. A stand-alone manager works across all your devices and browsers, which matters if your household mixes Windows, Mac, iPhone and Android.
The one we use ourselves is 1Password. It runs on Windows, Mac, Linux, iPhone and Android and in every major browser. Its Watchtower feature points out passwords that are weak, reused or known to have leaked, which makes it easy to see what to fix first. There is a family plan, so each person has a private vault plus shared ones for things like the streaming accounts.
Make the master password a passphrase. Four or five unrelated words are easier to remember and harder to crack than a short, complicated password. Something like copper-violin-staircase-Tuesday is far stronger than P@ssw0rd1. Make up your own, and do not reuse that example.
Write the master password down and keep the paper somewhere safe at home. A notebook in a drawer is not the risk. The risk is criminals on the other side of the world, and they cannot reach your drawer.
Habit two: two-step sign-in on the accounts that matter
Two-step sign-in, also called two-factor authentication or 2FA, means that after your password you confirm it is really you, usually with a code from your phone. A stolen password on its own is then useless.
Turn it on for these first:
- Your email. It is the key to everything else, because password reset links are sent there.
- Banking and anything that holds money
- Your Apple, Google or Microsoft account
- Your password manager
- Social media, which is often hijacked to scam your friends
Which kind of second step
From strongest to weakest:
- A passkey or a physical security key. The most secure, and increasingly the easiest.
- An authenticator app on your phone that shows a six-digit code.
- A code sent by text message. The weakest of the three, but far better than nothing. If it is the only option offered, use it.
Save the backup codes
When you turn on two-step sign-in, most services give you a set of one-time backup codes. Print them, or write them down, and keep them with your master password. They are how you get back in if your phone is lost or broken. People who skip this step are the ones who get locked out.
Never share a code
No real company will ever phone, text or email to ask you to read out a sign-in code. Anyone who asks for one is trying to get into your account at that moment. Hang up.
For a small business
- Give every person their own sign-in. Shared passwords cannot be traced, and they cannot be switched off when someone leaves.
- Use a password manager made for teams, so that access can be granted and removed without anyone seeing the password itself. 1Password has business plans built for this.
- Require two-step sign-in on email for everyone. Fake invoices sent from a hijacked mailbox are among the most expensive frauds a small business faces.
- Have a checklist for when someone leaves: accounts disabled, shared passwords changed.
Where to start today
- Turn on two-step sign-in for your email.
- Set up a password manager and put your email and bank accounts into it.
- Change any password you know you have reused, the important accounts first.
The rest can follow over time, as you sign in to each account.