Passwords & two-factor authentication

Two changes cover most of what goes wrong online: a unique password for every account, and a second factor on the accounts that matter.

Why this is the highest-value hour you will spend

Most account takeovers do not involve anyone breaking encryption. They happen because a password leaked from one service and worked on another. That attack is fully automated and costs the attacker almost nothing.

Two habits shut it down:

  1. A unique password per service – so one breach stays one breach.
  2. A second factor – so a stolen password on its own is not enough.
Where to start Do not try to migrate every account in one evening. Set up a password manager, then change passwords for your email account first, then anything with money attached. The rest can follow whenever you happen to log in.

The guides

First steps

Extra protection for the accounts that matter

For families and for planning ahead

Your email account is the master key

It is worth being blunt about this: whoever controls your email can reset the password on almost every other account you own. Banking, shopping, social media, cloud storage – all of them offer “forgot password”, and all of them send it there.

So if you only harden one account, harden that one: a long unique password, the strongest second factor available, and recovery codes stored somewhere offline.

What good looks like

WeakGood
Password length8–10 characters with symbolsa long passphrase of several random words
Reusesame password with small variationsunique per service
Storagememory, notebook, browserdedicated password manager
Second factornone, or SMS onlyauthenticator app or security key
Recoverynot thought aboutrecovery codes saved offline

The most common objection – “I can’t remember all that” – is exactly the point. You are not supposed to. That is the manager’s job.

All articles