Strong, Unique Passwords: Simple Habits That Protect Your Accounts
Learn how to make long passwords, choose memorable passphrases, and use a password manager. Start with one account today.
Strong, Unique Passwords: Simple Habits That Protect Your Accounts
A 4-minute guide · Safety Think about how many doors your email account can open. It holds personal messages, receipts, and links to reset passwords for other accounts. Giving it a good password is a small job with a big payoff.
The same goes for your other accounts. A few simple habits can help keep them safer, and you do not have to memorize a different jumble of characters for every website.
Give every account its own password
Imagine an old shopping website loses your login details in a data breach. Someone can then try that email address and password on other websites automatically. If you reused it for email or banking, those accounts could be at risk too.
Use a completely different password for each account. Changing just the final number or adding the website's name creates a pattern someone could guess.
Start with your main email account, then banking and other important accounts. You can work through the rest a few at a time.
Make it long and hard to guess
Aim for at least 16 characters, where the website allows it. A password manager can generate a random password of that length or longer. CISA recommends passwords that are long, random, and unique. CISA's password guidance
Avoid names, birthdays, familiar sayings, keyboard patterns, and passwords you have used before. Attackers use software to try common choices and predictable changes. Replacing a letter with a number does not fix a familiar password: Password1! is still easy to guess.
Follow a site's requirements for capitals, numbers, and symbols, but do not rely on those alone. Length matters more than making a short password look complicated. NIST's guidance on creating a good password
Try a passphrase when you need to remember it
A passphrase is a password made from several words. Use a password manager's random word generator to choose five to seven unrelated words. Avoid song lyrics, quotations, and sentences about your life.
For example, a passphrase might look like this:
lantern-cactus-violin-pebble-orbit
This is a public example. Do not use it as your password. Generate your own combination. Separators can make the words easier to read, as long as the website accepts them.
Let a password manager remember the rest
A password manager stores your logins in a protected vault. It can create a different password for each account and fill it in when you sign in. You can use one built into your device or browser, or a dedicated app.
When you change a password:
- Open the service's official app or use your saved website bookmark.
- Find its account or security settings and choose the password change option.
- Let your password manager generate a new password and save the updated login.
- Check that the saved login works before moving on to another account.
Protect the manager itself with a long, unique master passphrase if it uses one. Turn on multifactor authentication where available, and follow its instructions for keeping recovery information somewhere safe.
Add another layer of protection
Two-factor authentication, also called 2FA, asks for another check when you sign in, such as approval in an authenticator app. It helps protect your account if your password is stolen. Never share a sign-in code with an unexpected caller or approve a login you did not start.
If a service offers passkeys, consider setting one up. A passkey lets you sign in using your device's unlock method and helps protect against fake login websites. Make sure you understand how to regain access if you lose your device. NIST's explanation of MFA and passkeys
Your five-minute first step
Pick your main email account and check:
- Is its password different from every other account's password?
- Is it long and difficult to guess?
- Is the correct login saved in your password manager?
- Is two-factor authentication on, or have you set up a passkey?
- Are your recovery details up to date?
If you learn that a password has been exposed, change it promptly. Change it on any other accounts where you reused it, giving each a separate new password.
Remember: long, unique, and safely stored. Start with one account today.