Staying Safe Online: Scams, Passwords and 2FA Passwords: Why Yours Is Probably Already Leaked
2 / 5
Next
Passwords: Why Yours Is Probably Already Leaked ~15min

The real danger is reuse

Companies get breached constantly. When one leaks, attackers take those email-and-password pairs and try them everywhere else automatically. That is credential stuffing, and it is why one weak site can cost you your email account.

Length beats complexity

P@ssw0rd! is short, predictable and in every cracking dictionary. correct-horse-battery-staple is far stronger and far easier to type. Four random words beats symbol soup.

Use a password manager

Bitwarden is free. It generates a different long random password per site and fills it in for you. You memorise ONE strong master password and nothing else, and it also refuses to autofill on a lookalike domain, which quietly protects you from phishing.

Protect the email account first

Whoever controls your email can reset every other account you own through "forgot password". It deserves your strongest password and your best second factor, before anything else.

Check your exposure

haveibeenpwned.com tells you which breaches include your address. Most people find several. Change those, and stop reusing.

Tasks
Preview