GUIDE SecurityPasswordsAccounts

Passwords: The Only Three Things That Actually Matter

Guide 10 min read

Password advice is unusually bad. Most of it is a decade out of date, some of it actively makes things worse, and almost all of it is too long to act on.

Three things do nearly all of the work.

One: unique, everywhere

This is the whole game and everything else is detail.

The way ordinary people get compromised is almost never “someone guessed my password”. It is: a company you signed up to in 2016 got breached, your email address and password ended up on a list, and somebody typed that pair into a hundred other sites automatically. That attack is called credential stuffing and it is the bulk of the problem.

A unique password per site makes that attack fail completely. Not “harder” — it fails, because the stolen pair only opens the door it came from.

INSIGHT

Strength protects you against guessing. Uniqueness protects you against everyone else’s bad security. The second threat is far more common and entirely out of your control, which is why uniqueness beats complexity every time.

Two: long beats clever

correct horse battery staple is a better password than P@ssw0rd!, and it is easier to type on a phone.

Length is what makes a password expensive to crack; character variety adds much less than the rules imply, mostly because everybody satisfies the rules identically — a capital letter at the start, a number and an exclamation mark at the end. Attackers know that shape.

So: four or five unrelated words for anything you have to type by hand, and long random strings from a manager for everything else.

Three: a second factor on the accounts that matter

Two-factor authentication means a stolen password on its own is not enough. On your email account, this is the difference between an incident and a catastrophe.

Prefer an authenticator app or a hardware key over SMS. Text-message codes are much better than nothing and are vulnerable to somebody persuading a phone shop to move your number to their SIM — which is a real, routine attack, not a hypothetical.

CAUTION

Turn on two-factor for your email FIRST. Every other account you own can be reset through that inbox, so it is not one account among many — it is the key to all of them.

The part everybody skips: recovery

Here is the scenario that catches careful people: the phone with your authenticator app on it is lost, stolen or dead. Your passwords are in a manager you can only unlock on that phone. The codes to get back in are in the app on that phone.

You are now locked out of your own life by your own security.

The fix takes fifteen minutes:

  • Print the recovery codes for your email and your password manager. Put them somewhere physical — a drawer at home, an envelope with a trusted person. Paper is not a weak link here; the threat model for your kitchen drawer is very different from the threat model for the internet.
  • Write down the disk encryption key for your computer, and store it away from the computer.
  • Register a second factor, not just one. Two hardware keys, or an app plus printed codes.
  • Know where the list is without needing a device to tell you.

What you can safely ignore

  • Forced rotation. Changing good passwords on a schedule makes them worse.
  • Password hints. They are a clue for you and a clue for everybody else.
  • Security questions. Your mother’s maiden name is not a secret. Treat them as extra passwords: answer them with random strings and store the answers with the password.
  • The strength meter. It measures the shape of the password, not whether it is already on a list.

Where to start tonight

  1. Turn on two-factor for your email.
  2. Print its recovery codes and put them in a drawer.
  3. Change the password on your email to something long and unique.
  4. Install a manager and let it take over as you sign into things over the coming weeks — not all at once, or you will abandon it.

That is ninety percent of the benefit, and only the first three are urgent.

If you are setting up a machine from scratch, the new machine checklist puts these in the right order alongside everything else worth doing on day one — recovery first, then backup, then data. It is free.

📦

What's Included

Know which three habits do nearly all the work, and stop worrying about the rest
Understand why reuse — not weakness — is what actually gets people breached
Have a recovery plan that works when the phone with your codes on it is the thing that broke
Lifetime updates included

Frequently Asked Questions

You need somewhere unique passwords can live that is not your memory, because unique-everywhere and memorised are mutually exclusive past about five accounts. A manager is the practical answer; a notebook in a locked drawer is a real, if limited, alternative that security professionals will grumble about and which is still enormously better than reusing one password everywhere.
No, and current guidance from the standards bodies agrees. Forced rotation makes people pick weaker, more predictable passwords and write them on things. Change a password when there is a reason to — a breach, a shared device, a suspicion — and otherwise leave good unique passwords alone.
Nearly. Length matters far more than character variety: a long passphrase of ordinary words beats a short string of punctuation. Complexity rules mostly succeed at making passwords annoying to type and predictable in shape, because everybody satisfies them the same way — a capital at the front and a number and a bang at the end.
Your email. Everything else can be reset through it, which means whoever holds your email holds everything. If you only ever harden one account, harden that one, and give it a second factor that does not rely on your phone number.
Share this guide: