Passwords can feel complicated because every website has different rules, but the security goal is straightforward: if one password is stolen, it should not unlock several of your other accounts.
The easiest way to reach that goal is to use a different password for every important account, let a password manager remember them, and add two-factor authentication wherever it is available.
What makes a password safer?
A safer password is unique to one account and difficult to guess. Length is generally more useful than trying to create a short, complicated-looking password that you then reuse everywhere.
1. Use a different password for every important account
Password reuse is dangerous because a password exposed by one company can be tried against your email, shopping, social-media, or financial accounts.
Prioritize unique passwords for email, banking, payment services, cloud storage, social media, your mobile-carrier account, and any account that can reset other passwords.
2. Make passwords long
When you create a password yourself, use a long password or passphrase that is not based on easily discovered personal information. Follow the service's password requirements, but do not rely on predictable substitutions such as replacing an “a” with “@” as your main protection.
3. Use a password manager
A password manager can generate and store unique passwords so you do not have to memorize every one. This makes it practical to stop reusing passwords across dozens of accounts.
Protect the password manager itself with a strong master password and two-factor authentication when available.
4. What is two-factor authentication?
Two-factor authentication—often called 2FA, two-step verification, or multi-factor authentication—adds another sign-in check after the password. Depending on the service, the second step may be an authenticator app, security key, text message, device prompt, or another method.
If a criminal steals only your password, that extra step can prevent them from signing in.
5. Which type of 2FA should you use?
Use the strongest practical method the service supports and that you can reliably recover. Hardware security keys and authenticator-based or passkey methods can provide strong protection against certain phishing attacks. Text-message codes still add protection compared with using only a password, though they have additional risks.
6. Never give someone your security code
A one-time code is part of your sign-in process. An unexpected caller or texter asking you to read the code may be attempting to enter your account at that moment.
Likewise, do not approve an unexpected sign-in notification simply to make it disappear.
7. Save account-recovery information
Two-factor authentication is only useful if you can recover your account after replacing or losing a device. Save backup codes or recovery methods in a secure place and keep recovery email addresses and phone numbers current.
How to set up two-factor authentication
- Go directly to the service's official website or app.
- Open Security, Sign-in, Account, or Privacy settings.
- Look for Two-Factor Authentication, Two-Step Verification, Multi-Factor Authentication, passkeys, or similar wording.
- Choose a supported method.
- Follow the service's setup instructions.
- Save any recovery codes securely.
- Sign out and make sure you understand the new sign-in process.
Your 30-second password check
- Does my email have a password I use nowhere else?
- Do my banking and payment accounts have unique passwords?
- Am I using a password manager or another reliable way to maintain unique passwords?
- Is 2FA enabled on my most important accounts?
- Would I know how to recover those accounts if I lost my phone?
What if one of your passwords was exposed?
Change the password through the legitimate website or app. If you reused that password anywhere else, change those accounts too. Review recent sign-in activity, sign out unknown sessions, and enable two-factor authentication.
What if you receive an unexpected 2FA code?
Do not share it. Someone may have typed your password or attempted account recovery. Open the account through its official app or website, review security activity, and change the password if you see suspicious activity or believe the password may be known.
What about passkeys?
Some services now support passkeys, which can replace or supplement traditional passwords and can provide strong resistance to many phishing attacks. If a service you trust offers passkeys and you are comfortable with its recovery process, they can be a useful security option. You do not need to convert every account at once.
What not to do
- Do not reuse one favorite password across important accounts.
- Do not email or text passwords to yourself as your primary storage method.
- Do not give unexpected contacts one-time security codes.
- Do not approve an unexpected sign-in request.
- Do not ignore account-recovery options until after you lose a device.
How do you know you are safer?
Your most important accounts should each have a unique password or modern passwordless protection, 2FA where appropriate, current recovery information, and no unexplained sign-in activity.
The Know Phishing takeaway
Use unique passwords, let a password manager handle the difficult part, turn on two-factor authentication, protect your security codes, and make sure you can recover your accounts.