Category: Quick Guide / Technology
⚡ Creating & Managing Strong Passwords
Strong passwords help protect your email, money, medical information, photos, social media, and other personal information.
Use this guide when creating a new password, improving your password habits, or responding to a security warning.
The Three Most Important Rules
Every important password should be:
- Long
- Unique
- Safely stored
Do not reuse the same password for several accounts. If one company experiences a data breach, criminals may try that password on your other accounts.
Creating a Strong Password
Aim for at least 15 characters whenever the account allows it. Longer passwords are generally harder to guess.
One option is a passphrase made from several unrelated words. Add numbers or symbols if the website requires them.
A strong password should not contain easily guessed information, such as:
- Your name
- Your birthday
- Your address
- Your phone number
- Your child’s or pet’s name
- Your favorite sports team
- The name of the website
- Simple patterns
- Common words or phrases
Do not use examples printed in an article as your actual password.
Avoid Predictable Passwords
Do not use passwords such as:
passwordpassword123qwerty123456letmein- Your name followed by your birth year
- The same word with an exclamation point added
- A password you have already used elsewhere
Changing one letter or number in an old password does not make it truly unique.
Give Every Account a Different Password
Use a separate password for each account, especially:
- Banking and credit cards
- Medical portals
- Government accounts
- Cloud storage
- Shopping accounts
- Social media
- Work or school
- Your phone and computer
- Your password manager
Your email password is especially important because email is often used to reset passwords for your other accounts.
Use a Password Manager
A password manager can:
- Create long, random passwords
- Store them securely
- Fill them in for you
- Keep each account’s password unique
- Warn you about reused or compromised passwords
- Synchronize passwords across trusted devices
Your phone, tablet, computer, or browser may already include a password manager. You can also choose a separate trusted password-management service.
Before choosing one:
- Make sure it comes from a reputable company.
- Download it from the official website or app store.
- Review its recovery options.
- Protect it with a strong master password.
- Turn on multifactor authentication.
- Keep recovery information somewhere safe.
Your master password should be unique and should never be reused for another account.
Helpful Resources: Browse Password Management for products, equipment, services, or supplies related to this section.
If You Write Passwords Down
Writing passwords down may be safer than reusing a weak password, but the record must be protected.
If you keep a written password record:
- Store it in a secure private location.
- Do not leave it beside your device.
- Do not label it “Passwords” if other people can access the area.
- Do not carry your complete password list in your wallet or phone case.
- Never photograph the list and leave the photo unprotected.
- Update the record when a password changes.
A password manager is usually easier to protect and maintain than a paper list.
Turn On Multifactor Authentication
Multifactor authentication may also be called:
- MFA
- Two-factor authentication
- Two-step verification
- 2FA
It requires something in addition to your password, such as:
- An authenticator-app approval
- A one-time code
- A security key
- A fingerprint
- Facial recognition
- A passkey
Turn it on for important accounts whenever it is available.
An authenticator app, security key, or passkey may provide stronger protection than a code sent by text message. However, any available MFA is generally better than relying on a password alone.
Never Share a Verification Code
A bank, company, government agency, or support worker should not unexpectedly ask you to read back a one-time login code.
If someone asks for a verification code:
- Stop communicating with them.
- Do not approve a login notification.
- Do not provide the code.
- Open the official app or website yourself.
- Check the account for unfamiliar activity.
- Change the password if you believe someone tried to enter the account.
A verification code is meant to prove that you are the person signing in.
Save Recovery Codes Safely
Some accounts provide backup or recovery codes when you turn on MFA.
Store them:
- In your password manager
- In a secure locked location
- Somewhere separate from the device used for authentication
Do not send recovery codes through email or text, post them online, or store them where other people can easily find them.
Be Careful With Security Questions
Some websites still ask questions such as:
- What was your first school?
- What is your mother’s maiden name?
- What was the name of your first pet?
Answers may be available through public records or social media.
If the website permits it, use a unique answer that is not easily guessed and store it in your password manager. You do not have to use information other people already know about you.
Check the Website Before Entering a Password
Before signing in:
- Check the website address.
- Look for misspellings or unusual extra words.
- Avoid signing in through unexpected email or text links.
- Open the company’s official app or type its known address yourself.
- Stop if the page asks for information that does not make sense.
A password manager may help by filling a password only on the correct website, but you should still check the address.
Do Not Share Passwords Through
Avoid sending passwords through:
- Text messages
- Social media
- Online chat
- Unsecured notes
- Shared documents
- Unexpected support forms
Legitimate customer-service representatives should not need to know your password.
If another person needs access to an account, use an official sharing, family, delegate, or authorized-user feature when available.
When to Change a Password
Change a password if:
- You believe someone else knows it.
- The company reports a data breach involving passwords.
- You entered it on a suspicious website.
- You reused it on an account that was compromised.
- You notice an unfamiliar login.
- Your device was lost or stolen.
- Your password manager warns that it is compromised.
- Someone with authorized access should no longer have it.
You do not need to constantly change a strong, unique password for no reason. Frequent changes can lead to predictable passwords or unsafe recordkeeping.
If You Think an Account Was Compromised
Using a trusted device:
- Go directly to the account’s official app or website.
- Change the password.
- Make the new password long and unique.
- Sign out of other devices or active sessions.
- Turn on MFA.
- Review the recovery email and phone number.
- Check for unfamiliar activity or changes.
- Remove devices or apps you do not recognize.
- Change any other account using the same password.
- Contact the organization through a verified channel if needed.
Start with your email account if it may be affected, because it can often be used to reset other passwords.
If You Forget a Password
- Go to the official app or website.
- Select Forgot Password or Reset Password.
- Follow the recovery instructions.
- Check that messages come from the correct organization.
- Create a new, unique password.
- Save it securely.
- Review the account for unfamiliar activity.
Do not pay someone who contacts you unexpectedly and claims they can recover the password.
Quick Password Check
For each important account, ask:
- Is the password at least 15 characters when allowed?
- Is it unique to this account?
- Is it stored safely?
- Is MFA turned on?
- Are the recovery email and phone number current?
- Are recovery codes stored securely?
- Would someone who knows me be able to guess it?
Start with your email, banking, medical, and cloud-storage accounts if updating everything at once feels overwhelming.
