The short answer: a strong password is long, unique and has nothing to do with you. Nobody memorises dozens of them, and you do not need to: you keep them in a password manager and memorise just one, the one that opens the manager. Reusing the same password in several places is the mistake that turns one data leak into a break-in on everything you own.
Why reuse is the real danger
When any service suffers a data leak, the stolen passwords are tried, by programs, on every other service: your e-mail, your bank, your hosting account, WordPress. If you reused the password, the attacker has nothing to guess. They simply walk in. That is why the password you chose for an old forum matters as much as your e-mail one.
What makes a password strong
| Trait |
Why |
| Long |
Length counts for more than symbols. A phrase of four or five unrelated words is stronger, and easier to type, than eight characters full of symbols. |
| Unique to each service |
If one falls, the others stay up. This is the rule that matters most. |
| No personal details |
Children’s names, birthdays, the car plate, the company name and the phone number are the first things any attacker tries. |
| Random |
Words you pull out of your own head tend to be the ones everybody picks. Words a generator draws at random do not. |
How to get to unique passwords without going mad
| 1 |
Choose a password manager. There are apps for phone and computer that store passwords encrypted, fill them in for you and generate new ones. The one built into your browser will do if you protect it with your computer login and two-step verification; what matters is keeping passwords somewhere other than a note in a drawer or a file called “passwords.txt”.
|
|
| 2 |
Create a long master password, a phrase of your own that you never use anywhere else, and switch two-step verification on in the manager. See which kind of verification to pick.
|
|
| 3 |
Change the ones that matter most first: the recovery e-mail, My MozOut, cPanel, the WordPress administrator. Swap the rest as you use them.
|
|
| 4 |
Let the manager generate the new ones, or use our password generator. You never need to see or know them.
|
|
| 5 |
Ask yourself whether you have already been caught. Free public services, such as Have I Been Pwned, let you type your e-mail address and see whether it appears in known data leaks. If it does, change the password for that service and for any other where you reused it.
|
|
|
Do not send passwords by message or e-mail, not even to a colleague you trust. It stays in the conversation for ever. To give someone access, create them a login of their own, as explained in managing sub-accounts, and remove it when it is no longer needed.
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from KSh858.00/mo (3-year plan, with coupon) See plans |