Passwords

If you remember one thing from this page: using the same password on more than one site is the single biggest risk most people carry online. Here's why — and the one change that fixes it for good.

Why one reused password is dangerous

When a company gets hacked — and big ones do, regularly — the passwords people used there get stolen and sold. Criminals then try those same email-and-password combinations everywhere else: your bank, your email, your Amazon account. If you reuse a password, a break-in at any site opens all of them.

This has a name — credential stuffing — and it's worth a few minutes to see how it actually works.

A way to imagine this is that someone steals a key from a school janitor that opens a closet. If that key opens every door, then the criminal will have access to everything in the school until the janitor changes the locks on every door. But if the key only opens one door, then the criminal will have access to that closet but nothing else, and the janitor only needs to rekey that single door.

That's why the goal isn't a "stronger" password. It's a strong different password for every account — which no one can do from memory. Nobody's asking you to. That's what a password manager is for.

Let a password manager do the remembering

A password manager is a small program that invents strong, unique passwords and remembers them for you. You remember one good password — the one that opens the manager — and it handles every other account. It fills passwords in automatically, so day to day you actually type less than you do now.

Rememberable password 1978Valpo!, 1978Valpo!2, etc.
Secure password kF$bqyseLqSEoh78, CqrP7JzkhFkHsL#?

Do this today

If you use an iPhone, iPad, or Mac, you already own a good one: Apple Passwords is built in and free. If you use a mix of devices, Bitwarden or Proton Pass are both free and work everywhere, and Dashlane is an excellent paid option.

About the password notebook

Don't use a password notebook. Please don't. It's an all-around bad option.

Using a notebook with unique passwords is better than using the same password everywhere, but that is a very low bar.

"Sign in with Apple" or "Sign in with Google" is your friend

When a website offers a button that says Sign in with Apple or Sign in with Google, that's usually the safest choice. It means one less password to exist at all — the site never gets one from you — and Apple will even hide your email address if you ask it to.

Add a second lock to the accounts that matter

Two-factor authentication (you'll see it called 2FA or MFA) adds a second step when you sign in — usually a code sent to your phone or a rotating code that your password manager generates. It means that even if someone steals your password, they still can't get in without your phone. Turn it on for your email and your bank first: your email is the master key to everything else, because that's where "forgot password" links go.