Why One Strong Password Is Not Enough
A long password can be hard to guess, and yet open several accounts at once. The problem starts when you use it again.
In this guide
Let's assume that you log into the mail and the long-lost forum with the same address and password. Data leaks from the forum. If the attacker learns the password, he can check this pair in the post office, shop and social networking site. He does not have to break the security of each of them separately.
Auto-trying revealed login–password pairs on other pages is called credential stuffing. This is why “my password is very complicated” does not solve the problem of reuse.
Length and uniqueness solve other problems
Length and randomness make guessing a password difficult. Uniqueness limits the extent of damage after disclosure. You need both features.
The password created according to the scheme “continuous phrase + service name” also does not give good isolation. If you see one or two examples, you may know the rules. Adding a year, a digit or an exclamation mark is an easy change to predict.
You don’t have to invent dozens of secrets. The manager can generate and remember them for you. Create new passwords regardless of the previous one, without your own account binding pattern.
Which accounts should I start with?
Set a short queue according to the consequences of loss of access:
- Mail and password manager. They give access to other data, or they're for the recovery of accounts.
- Accounts with money and documents. Bank, payments, cloud and important service.
- Accounts that allow someone to impersonate you. Communicators, social profiles and credit card stores.
If you have confirmation of a specific leak, the account covered by the incident and all places with the same password come to the start of the queue.
Change without losing entries
Open one account settings. Generate a new password, save it to the right address and then confirm the change. Check the login in the second window, leaving the first session open.
An example of an organization: the entry “Shop — private email” is readier than three entries called “Shop”, each containing a different password. Do not delete the old record before you confirm which one is up to date.
Does 2FA allow you to leave a common password?
2FA provides protection, but does not remove the effects of password disclosure. Not all accounts have this feature; the emergency method can be weaker and the code can sometimes be extorted. The best practical layout is a unique password and an appropriate second method of login.
You do not need to change every password every month. When it is unique and there are no signs of compromise, it is more important to maintain access to the safe and respond to actual incidents. After cleaning, check the report of repeated passwords in your manager if he offers it.