BRF-04 / Password Security
Password security without memorizing forty passwords
The biggest password problem isn't weak passwords. It's reused ones. When one site is breached, criminals try the same email and password on banks, email and shopping sites. That's called credential stuffing, and it works because so many people use one favorite password everywhere.
The fix is less work than it sounds. A password manager creates and remembers a different password for every account, and you remember one strong passphrase to open it. Passkeys, now offered by many large services, go further by replacing the password with your phone's or computer's own screen lock.
This section covers choosing a password manager, writing a passphrase you'll actually remember, checking whether your email shows up in known breaches, and a sensible order for fixing old passwords. You don't have to change everything tonight. Start with email, then banking, then everything else.
Red flags
- You use the same password on more than one important account.
- A site emails you your actual password. It shouldn't be able to.
- You get a sign-in code you didn't request.
- Your password is a word plus a year, or a pet's name plus an exclamation mark.
5-minute security check
- Change your email password to a unique passphrase.
- Install a reputable password manager.
- Check your email address at haveibeenpwned.com.
- Turn on passkeys where your main accounts offer them.
Password Security briefings
No password security briefings are filed yet. The first one is in the works; until then, the headlines below track what’s happening.
Fraud and breach reporting from Krebs on Security
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters InvestigationKrebs on Security
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon ExtortionsKrebs on Security
- Data Broker Radaris Loses Domains in Privacy FightKrebs on Security
- Microsoft Plugs Nearly 1,000 Security HolesKrebs on Security
- FBI Probes Service Selling 153M+ Drivers LicensesKrebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in AustraliaKrebs on Security