Kasspar kasspar.com
LESSON 1 / of 6

Passwords & passphrases

Why length and uniqueness beat clever symbols, and what credential stuffing means for the password you used once, years ago.

Passwords & passphrases

Attackers rarely "guess" a password by hand. They use software that tries millions of candidates a second, starting with the ones people actually choose: lists of passwords leaked from past breaches, dictionary words with a capital letter and a number tacked on, the current season plus the year, a pet's name with an exclamation mark. If your password follows a pattern people use, it is in the list.

The second problem is reuse. When one website is breached, criminals take the email-and-password pairs and try them on every other major service. This is called credential stuffing, and it is why one old password from a forum you forgot about can open your email today.

What actually protects you is length and unpredictability, and never using the same password twice. A random string from a password manager is best. If you have to remember one, a passphrase of four or more unrelated words, like copper kettle whistles dawn, is far stronger than K3ttle!2026 and much easier to type.

Common myth"Changing my password every 90 days keeps me safe." Forced rotation mostly produces predictable tweaks (Summer2026 becomes Autumn2026). Change a password when there is a reason to, such as a breach, and make it long and unique the first time.
Do these
  1. Install a password managerLet it generate and remember a different password for every account. Your browser's built-in one is a fine start.
  2. Fix the four accounts that matter mostEmail, banking, phone carrier, and your main social account. Email first, because it resets all the others.
  3. Use a passphrase for the manager itselfFour or more unrelated words you can remember. Write it down and keep it somewhere physically safe if you need to.