Passwords and Password Management

Creating, managing, and protecting the keys to your digital life.

Why Passwords Matter

Your password is often the only thing between an attacker and your accounts. A weak or reused password is like using the same flimsy lock on your house, car, and bank vault.

Password ProblemReal-World Consequence
Weak passwordCracked in seconds to minutes
Reused passwordOne breach compromises everything
Written on sticky noteAnyone with access can see it
Shared with othersNo accountability or control
Never changed after breachAttacker retains access

What Makes a Password Strong

Length vs. Complexity

Length matters more than complexity:

PasswordStrengthTime to Crack
P@ssw0rdTerribleSeconds
MyDog2020!BadMinutes
K7$mP2@nQ9!ModerateHours to days
correcthorsebatterystapleGoodYears
Hk8$mN2@pL5!xR9wQj7ExcellentCenturies

Key insight: A 20-character password with just lowercase letters is stronger than an 8-character password with symbols.

Password Strength Formula

FactorImpact on Security
LengthExponential increase per character
Character varietyIncreases possible combinations
RandomnessPrevents dictionary attacks
UniquenessLimits breach damage

Bad Password Patterns

Attackers know these patterns:

PatternExamplesWhy It's Weak
Dictionary wordspassword, welcomeFirst thing attackers try
Name + numbersJohn1990, Mike2024Easily researched
Keyboard patternsqwerty, 123456Well-known sequences
Simple substitutionsp@ssw0rd, h3lloAttackers test these
Personal infoBirthday, pet nameFound on social media
Season + yearSummer2024!, Winter2023Common corporate pattern

Password Managers

You cannot remember strong, unique passwords for dozens of accounts. Use a password manager.

How Password Managers Work

  1. Generate random, strong passwords for each account
  2. Store them in an encrypted vault
  3. Auto-fill passwords in browsers and apps
  4. Sync across your devices
  5. You remember one master password
ManagerPriceBest For
1Password$3/monthFamilies, ease of use
BitwardenFree / $10/yearBudget-conscious, open source
Dashlane$5/monthExtra features (VPN, dark web monitoring)
KeePassXCFreeTechnical users, local-only storage

Setting Up a Password Manager

  1. Choose your manager - Any reputable one is better than none
  2. Create master password - Make it very strong and memorable
  3. Install everywhere - Browser extensions, phone apps, desktop
  4. Import existing passwords - Start from browser or old manager
  5. Audit and replace - Change weak and reused passwords
  6. Enable 2FA on the manager - Protect the master vault

Master Password Strategy

Your master password must be:

  • Memorable (you can't store it in the manager)
  • Long (16+ characters minimum)
  • Unique (never used anywhere else)
  • Resistant to guessing

Passphrase method:

StepExample
Pick 4-5 random wordscorrect horse battery staple
Add personal twistCorrect-Horse-Battery-STAPLE-42
Make it memorableCreate a mental image

Never forget this password. Consider a secure physical backup.

Password Hygiene

The Golden Rules

RuleReason
One password per accountBreach containment
Minimum 16 charactersCracking resistance
Randomly generatedNo patterns to exploit
Never share passwordsAccountability and security
Change after any breachRemove attacker access

When to Change Passwords

SituationAction
Account in known breachChange immediately
Shared with ex-partnerChange immediately
Suspicion of compromiseChange immediately
Regular scheduleNot necessary with unique passwords
Company policy requiresComply, but use password manager

Password Security Questions

Security questions are effectively backup passwords. Treat them that way:

Bad ApproachBetter Approach
Real mother's maiden nameRandom answer stored in manager
Actual first carUnrelated word or phrase
Real hometownNonsense answer you can retrieve

Why: Answers to real questions can be researched or guessed.

Checking for Compromises

Have I Been Pwned

Visit haveibeenpwned.com to check if your email appears in known breaches:

  1. Enter your email address
  2. See list of breaches containing your data
  3. For each breach, change that password
  4. If password was reused, change everywhere

Signs Your Password May Be Compromised

Warning SignWhat to Do
Login notification you didn't triggerChange password, check account activity
Password reset email you didn't requestChange password, enable 2FA
Account locked for failed attemptsSomeone is trying to get in
Unknown devices in account settingsRemove them, change password
Friends receive spam "from you"Account likely compromised

Special Cases

Shared Accounts

For accounts that must be shared (family Netflix, etc.):

DoDon't
Use password manager sharing featureText or email passwords
Create dedicated shared vaultReuse passwords from personal accounts
Update when sharing endsUse guessable passwords for convenience

Work vs. Personal

RecommendationReason
Separate password managersCompany may have access to work manager
Never reuse between work/personalBreach at one doesn't affect other
Follow company security policiesLegal and professional obligation

Device Passwords and PINs

DeviceMinimum Recommendation
Computer login12+ character password
Phone unlock6-digit PIN minimum (biometric + PIN ideal)
TabletSame as phone
Smart home hubUnique, strong password

WiFi Passwords

RecommendationReason
WPA3 or WPA2 onlyOlder protocols are broken
20+ random charactersNetworks are long-term targets
Change if shared widelyLimit who has access
Guest network for visitorsDon't share main password

Common Password Mistakes

MistakeWhy It's Dangerous
Using browser's "remember" without master passwordAnyone with device access can see passwords
Storing in notes appUsually not encrypted
Emailing passwordsEmail isn't secure
Using same password "with variations"Easily guessed from one known password
Password hints that reveal passwordDefeats the purpose
Not logging out of shared computersNext user has your access

Password Recovery

Setting Up Account Recovery

Recovery OptionSecurity LevelConvenience
Backup codes (save in manager)HighModerate
Recovery email (secured with 2FA)GoodGood
Phone numberModerate (SIM swap risk)Very easy
Security questionsLowEasy

What If You're Locked Out

  1. Use recovery codes if you saved them
  2. Try recovery email - ensure that account is also secure
  3. Contact support - prepare identity verification
  4. Learn from it - set up better recovery options

Password Manager Emergency Access

What happens to your passwords if you're incapacitated?

ManagerEmergency Access Feature
1PasswordShared vaults, emergency kit
BitwardenEmergency access contacts
DashlaneEmergency contact feature
KeePassXCShare vault file + password

Plan ahead: Document how trusted family members can access critical accounts.

Transitioning to a Password Manager

Phase 1: Critical Accounts (Week 1)

Account TypeAction
Email (primary)Add to manager, enable 2FA
Bank/FinancialAdd to manager, enable 2FA
Password manager itselfStrong master password, 2FA

Phase 2: Important Accounts (Week 2-3)

Account TypeAction
Social mediaAdd to manager, update to unique password
Shopping sitesAdd to manager, especially if card stored
Cloud storageAdd to manager, enable 2FA

Phase 3: Everything Else (Ongoing)

  • Add accounts as you use them
  • Generate new password when adding to manager
  • Audit for old reused passwords
  • Delete unused accounts

Key Takeaways

  1. Length beats complexity - 20 characters of lowercase is better than 8 characters with symbols
  2. Never reuse passwords - One breach should never compromise multiple accounts
  3. Use a password manager - You cannot remember good passwords for all your accounts
  4. Master password is critical - Make it strong, memorable, and unique
  5. Check haveibeenpwned.com - Know if your credentials are in breaches
  6. Security questions need random answers - Store fake answers in your manager
  7. Set up account recovery - Don't get locked out of important accounts
  8. Plan for emergencies - Trusted family should be able to access critical accounts
  9. Transition gradually - Start with critical accounts, then expand
  10. Generate, don't create - Let the password manager create passwords for you