BRF-04 / Password Security

Password security without memorizing forty passwords

The biggest password problem isn't weak passwords. It's reused ones. When one site is breached, criminals try the same email and password on banks, email and shopping sites. That's called credential stuffing, and it works because so many people use one favorite password everywhere.

The fix is less work than it sounds. A password manager creates and remembers a different password for every account, and you remember one strong passphrase to open it. Passkeys, now offered by many large services, go further by replacing the password with your phone's or computer's own screen lock.

This section covers choosing a password manager, writing a passphrase you'll actually remember, checking whether your email shows up in known breaches, and a sensible order for fixing old passwords. You don't have to change everything tonight. Start with email, then banking, then everything else.

Red flags

  • You use the same password on more than one important account.
  • A site emails you your actual password. It shouldn't be able to.
  • You get a sign-in code you didn't request.
  • Your password is a word plus a year, or a pet's name plus an exclamation mark.

5-minute security check

  • Change your email password to a unique passphrase.
  • Install a reputable password manager.
  • Check your email address at haveibeenpwned.com.
  • Turn on passkeys where your main accounts offer them.

Password Security briefings

No password security briefings are filed yet. The first one is in the works; until then, the headlines below track what’s happening.

Fraud and breach reporting from Krebs on Security

Keep reading

Follow on Google News