Passwords & two-factor authentication
Two changes cover most of what goes wrong online: a unique password for every account, and a second factor on the accounts that matter.
Why this is the highest-value hour you will spend
Most account takeovers do not involve anyone breaking encryption. They happen because a password leaked from one service and worked on another. That attack is fully automated and costs the attacker almost nothing.
Two habits shut it down:
- A unique password per service – so one breach stays one breach.
- A second factor – so a stolen password on its own is not enough.
The guides
First steps
- Password managers explained – what they do, why the browser’s built-in store is not quite the same, and how to start.
- Choosing a master password – the one rule that counts.
- Password strength check – measure a password in your browser, nothing transmitted.
Extra protection for the accounts that matter
- Two-factor authentication – which method to choose and where to turn it on first.
- Passkeys explained – signing in with no password at all.
For families and for planning ahead
- Password managers for families – sharing logins safely instead of passing paper around.
- Digital legacy – emergency access, so nobody stands in front of a locked door.
Your email account is the master key
It is worth being blunt about this: whoever controls your email can reset the password on almost every other account you own. Banking, shopping, social media, cloud storage – all of them offer “forgot password”, and all of them send it there.
So if you only harden one account, harden that one: a long unique password, the strongest second factor available, and recovery codes stored somewhere offline.
What good looks like
| Weak | Good | |
|---|---|---|
| Password length | 8–10 characters with symbols | a long passphrase of several random words |
| Reuse | same password with small variations | unique per service |
| Storage | memory, notebook, browser | dedicated password manager |
| Second factor | none, or SMS only | authenticator app or security key |
| Recovery | not thought about | recovery codes saved offline |
The most common objection – “I can’t remember all that” – is exactly the point. You are not supposed to. That is the manager’s job.
All articles
Password strength check
How strong is your password? Check it here, right in your browser, against the NIST guidelines. What you type never leaves your device and is never stored.
Password managers explained
One strong password to remember, unique passwords everywhere else – and a quiet side effect that blocks phishing automatically.
Two-factor authentication: which method and where first
A second factor means a stolen password is not enough on its own. Not all methods are equal though – and the differences matter most exactly where your money …
Passkeys explained: signing in without a password
Passkeys replace the password: you sign in with your fingerprint, your face or your device PIN – phishing-proof and easier day to day. Here is how it works.
Digital legacy: sorting out access before it is needed
What happens to your accounts if something happens to you? Without preparation, the people close to you stand in front of locked doors. Here is how to sort out …
Choosing a master password: the one rule that counts
Your master password protects every other password you have – it is the skeleton key. Here is how to pick one that is strong and still memorable.
Password managers for families: sharing without the sticky notes
A family plan protects everyone in the household, not just you – and finally makes sharing the Wi-Fi and streaming logins safe. What matters, and who needs …