Reusing passwords is the single most common way accounts get taken over. When one site is breached, attackers try that same password everywhere else. The fix is a unique password for every account, and you don't have to memorize a single one other than the one for the password manager.
Step 1: Let a password manager do the work
A password manager generates a strong, random password for every site and stores them behind one master password. It syncs across your devices, so you always have them. Pick one, and let it create passwords you'll never see or type.
Two things to know: it's a single point of failure, and a target. So protect it with a strong master password and turn on two-factor authentication.
Step 2: Make a few passwords strong by hand
A handful of passwords you should memorize: your device, your disk encryption, your email, and your password manager's master password.
People are bad at being random. So use EFF's method: roll dice against a word list and string together at least six random words into a "passphrase." Six random words is long, memorable, and very hard to guess. (EFF publishes the word lists free at eff.org/dice.)
Step 3: Lie on your security questions
"What was your first pet's name?" is often findable online. Don't answer honestly. Generate a random answer in your password manager and store it there. Different fake answers for every site.
Step 4: Turn on two-factor, the right way
Two-factor means a password plus a second code. When you can choose, pick an authenticator app or a hardware key (like a YubiKey) over text-message codes. SMS codes can be redirected to an attacker's phone; app and hardware codes can't.
Save your backup codes somewhere safe. Lose your second factor with no backup, and you can be locked out for good.
Privacy is a practice. We help you get started.
Up next · Monday
The week's most important privacy story, in plain English: what happened, why it matters, and what to do about it.
