Passwords you do not have to remember
The problem was never that your password is weak. It is that you use it twice.
Why reuse is the real danger
Companies get broken into. When one does, the passwords taken from it get tried everywhere else — automatically, on millions of accounts, within hours. If your shopping password is also your email password, one shop's bad day becomes your bad year.
A long password used in two places is weaker than a short one used in one.
What to do instead
Let something else remember them. Your phone and your browser both have a password manager built in, already paid for, and it is enough:
- It creates a different password for every site
- It fills them in for you
- It refuses to fill one in on the wrong site, which quietly protects you from fake pages
You then have to remember exactly one password: the one that opens the manager. Make that one long.
What a good one looks like
Length beats complexity. Four or five unrelated words is stronger than P@ssw0rd! and far easier to type on a phone.
Do not use: your name, your birth year, your children's names, your football team, or the city you live in. Anyone who wants in can find all of those.
Where to start
You do not have to fix everything today. Change these three first, because everything else can be reset through them:
- Your email
- Your phone account
- Your bank
The rest can wait until the manager offers to change them.
If a site emails you your own password when you forget it, that site is storing it in plain text. Assume it will leak, and never reuse that password anywhere.