Does your password habit go something like this? Your favorite sports star or celebrity, a capital first letter, a 3 where the "e" should be, and an exclamation mark on the end, M3ssi10!
If so, you're far from alone, and it isn't your fault. For years, many websites wouldn't let you create an account unless your password had a capital letter, a number and a symbol. So people added those things in the easiest way they could think of, and the same few tricks spread everywhere.
The trouble is that these passwords are much easier to crack than they look. NIST is a US government agency that publishes technology guidelines. It advises against requiring mixtures of different character types, and its newest version is firmer, saying organizations must not add such rules beyond a minimum length and a check against known-leaked passwords.
Here's what works, and why.
1. Length matters more than complexity
Attackers rarely guess by hand. Software tries combinations at enormous speed, which is called a brute-force attack.
Picture a bike lock. Three dials means 1,000 combinations, and every extra dial multiplies that by 10. Passwords work the same way, except each character on a keyboard (letters, numbers and symbols) has about 95 options instead of 10. Eight random characters gives roughly 6,600,000,000,000,000 combinations. That sounds enormous, but computers are fast enough that it protects you less than it seems.
So the goal is length, built from random words. This is called a passphrase. Security experts measure unpredictability in "bits" and each extra bit doubles the number of guesses an attacker needs. The EFF, a digital-rights nonprofit, explains that a six-word passphrase from their 7,776-word list has about 77 bits, and they recommend that for most uses.
You'll often see four words suggested. It's a good start, though the math says it's a bit short. Four random words is about as strong as eight random characters. That's fine for a low-stakes account. For your email and for your password manager's master passphrase (more on that below), six words gives you much more room.
One gentle catch: the words need to be random.
Use dice or a passphrase generator, which picks the words for you. When people choose their own, they lean toward common words, and four-word phrases they pick rarely get past about 30 bits of real unpredictability.
2. Give every account its own password
Think of your accounts as doors. If one key opens your front door, your car and your gym locker, a lost gym key becomes a much bigger problem than if the key for each was unique and separate.
Here's how that played out for real. 23andMe is a DNA-testing company. Starting April 29, 2023, an attacker spent about five months feeding usernames and passwords from other breached websites into its login page until matches were found. This is called credential stuffing. About 14,000 accounts were accessed directly, and through them the attacker viewed information in roughly 5.5 million DNA Relatives profiles and 1.4 million Family Tree profiles. Those are optional features that match customers with genetic relatives who also use the service.
23andMe's response pointed to users recycling passwords, some security experts felt that placed too much blame on customers. Reuse made the attack possible, but the company's defenses mattered too. Their security did not require a multi factor authentication at login at the time, which we'll cover below.
You might wonder why anyone would care about your account. It's a natural thought. The thing is, nobody picked those 14,000 people. A program tried every login it had, and those 14,000 accounts happened to be on the list.
3. Let a password manager do the remembering
Unique, long passwords for dozens of accounts is more than most of us can hold in our heads. A password manager is an app that keeps all your passwords in one protected place, a bit like a digital safe. It opens with a single master passphrase, so that's the only one you need to remember, and it's a good place for your six words. Many password managers can also create random passphrases for you.
You might wonder if keeping all your passwords in one place makes it a big target. That's a fair concern. Still, without a manager, many people fall back on reusing passwords, and we just saw what that can cost.
Password managers can also help with fake websites. Bitwarden, for example, suggests a saved login only when the website's address matches the one you saved, so a lookalike address usually won't get a suggestion. It isn't foolproof, since you can override it by hand, so it's still worth glancing at the address yourself.
4. Add a second lock with two-factor authentication (2FA)
2FA means logging in takes two things: something you know (your password) and something you have (your phone or a small device).
Google studied this with NYU and UC San Diego. It looked at attacks by bots, which are automated programs that try logins nonstop, and by phishing, where a fake message or website tricks you into handing over your login. A code texted to a recovery phone blocked 100% of automated bots, 96% of bulk phishing attacks and 76% of targeted attacks. On-device prompts blocked 100% of bots, 99% of bulk phishing and 90% of targeted attacks. Only a security key was effective against every category. That study covered Google accounts, so treat the numbers as a strong signal, not a promise for every site.
Here are the common options, in plain words:
- Texted code: a code sent to your phone. Any second check beats none, but CISA, the US cyber-defense agency, treats this as the weakest kind.
- Authenticator app: an app that shows a short code that changes every few seconds. A fake website can still trick you into typing that code in.
- On-device prompt: a pop-up on your phone asking whether it's you signing in.
- Security key: a small external device that connects to your computer or phone, and it's the most resistant to phishing.
Where to start today
You can start today, and you don't have to do it all at once. It can feel a bit overwhelming to take on every account at the same time, so let's go one step at a time. A good first step is your primary email. If someone gets into it, they can click "Forgot password" on your other accounts and the reset links arrive in their hands.
1. Set a six-word passphrase for your email. Use dice or a generator.
2. Turn on 2FA for that email. Choose an on-device prompt or authenticator app over texts if you can.
3. Install a password manager. Let it create unique passwords as you go.
4. Update the rest over time. A few accounts a week is plenty, starting with money and anything linked to your email.
In short: make your passwords long, give each account its own, and add a second lock. Those three habits are a strong foundation, and you can build them at your own pace.
REFERENCES:
NIST guidance: pages.nist.gov/800-63-3/sp800-63b.html
NIST agency background: kuppingercole.com/vendors/nist
Rev. 4 wording: enzoic.com/blog/nist-sp-800-63b-rev4/
EFF passphrases: eff.org/deeplinks/2016/07/new-wordlists-random-passphrases
EFF nonprofit status: eff.org/about
95 printable characters: github.com/alanbarr/diceware
Human-chosen phrases: en.wikipedia.org/wiki/Passphrase
23andMe account: blog.23andme.com/articles/addressing-data-security-concerns
23andMe timeline and MFA: security.org/identity-theft/breach/23andme/
23andMe features: customercare.23andme.com/hc/en-us/articles/360036068393-The-23andMe-Family-Tree-Feature
Blame dispute: theregister.com/2024/01/04/23andme_victim_blaming_breach/
Bitwarden generator: bitwarden.com/blog/how-to-use-the-bitwarden-passphrase-generator/
Bitwarden autofill: bitwarden.com/help/auto-fill-browser/
Google 2FA research: security.googleblog.com/2019/05/new-research-how-effective-is-basic.html
Security key result: tripwire.com/state-of-security/adding-a-recovery-phone-number-blocks-100-of-automated-bot-attacks-finds-google
CISA on security keys: cisa.gov/require-multifactor-authentication
CISA on weaker
MFA: securityweek.com/cisa-urges-organizations-implement-phishing-resistant-mfa
