Passwords & passphrases
Attackers rarely "guess" a password by hand. They use software that tries millions of candidates a second, starting with the ones people actually choose: lists of passwords leaked from past breaches, dictionary words with a capital letter and a number tacked on, the current season plus the year, a pet's name with an exclamation mark. If your password follows a pattern people use, it is in the list.
The second problem is reuse. When one website is breached, criminals take the email-and-password pairs and try them on every other major service. This is called credential stuffing, and it is why one old password from a forum you forgot about can open your email today.
What actually protects you is length and unpredictability, and never using the same password twice. A random string from a password manager is best. If you have to remember one, a passphrase of four or more unrelated words, like copper kettle whistles dawn, is far stronger than K3ttle!2026 and much easier to type.
- Install a password managerLet it generate and remember a different password for every account. Your browser's built-in one is a fine start.
- Fix the four accounts that matter mostEmail, banking, phone carrier, and your main social account. Email first, because it resets all the others.
- Use a passphrase for the manager itselfFour or more unrelated words you can remember. Write it down and keep it somewhere physically safe if you need to.