A strong password is long and unique. It is not “P@ssw0rd1” with a clever substitution. Attackers try those patterns first. A four-word phrase you have never posted online, plus a password manager so you are not recycling the phrase on every site, beats a 10-character tangle you write on a sticky note.

What you need

  • A password manager you will actually open (Bitwarden, 1Password, or the one built into the browser — pick one)
  • Five minutes to change the three accounts that matter: email, bank, the store you use weekly

1. Build a passphrase

Pick four unrelated words you can picture: kettle-orchid-tram-copper. Add a number or a short tag for the site only if the site still has silly complexity rules: kettle-orchid-tram-copper-mail. Length is what hurts guessing. A 20+ character phrase is stronger than Tr0ub4dor&3.

Do not use song lyrics, your street, or your kid’s name plus a year. Those are in dictionaries. Do not use a phrase you have tweeted.

2. One password per site

If a shop is breached, reused passwords are how the attackers open your email next. The email account is the skeleton key because “forgot password” on everything else goes there. Make the email password unique first. Then the bank. Then the rest as you log in, not all in one panicked night.

3. Let a manager remember them

Install one password manager. Create a vault password that is a long passphrase you will not reuse anywhere else. Write that vault password on paper and put it in a drawer if you must — that is safer than a weak vault password you will reset every month.

When a site offers Generate, use it. Save. Autofill next time. The manager’s random 20-character string is fine because you never type it.

Browser-built-in managers are better than a notebook. A dedicated manager is better if you use more than one browser or a phone and a PC.

4. Turn on two-step verification

On Gmail, Microsoft, your bank, and Apple: turn on 2-step verification. An authenticator app is better than SMS. SMS is still better than nothing. Save the backup codes the site shows you, in the manager or on paper. Without those codes, a lost phone becomes a locked account.

What not to do

Habits that cancel the work

  • Emailing yourself a list of passwords.
  • The same phrase plus the site name only (kettle-facebook). Attackers try that too.
  • Sharing a Netflix password in a family WhatsApp that also has cousins you barely know — that is a different problem, but it is how “private” logins leak.
  • Turning off 2-step because it annoyed you once at an airport. Add a second method instead.

If a mail already tricked you into typing a password, change that password from a device you trust, turn on 2-step, and read how to check a site before you type anything.

Common questions

Are four random words really stronger than symbols?

Length wins. A 20+ character passphrase beats P@ssw0rd1. Skip lyrics and family names. Use a manager for unique site passwords.

Is the browser’s password saver OK?

Better than a notebook. A dedicated manager is better if you use more than one browser or a phone and a PC.

SMS codes feel annoying. Can I skip 2-step?

Do not skip it on email and banking. An authenticator app is smoother than SMS. Save the backup codes.