Home / Articles / Passwords

   

Forward

This page goes over a few simple steps you can take today to improve the security of your online accounts. Here are the key takeaways:

  1. A long and simple to remember password is better than a short obtuse one.
    • Consider a password like "Correct9-Horse0-Battery2-Staple1" over one like "Tr0ub4dor".
  2. You should really enable MFA on (at least) your most important accounts.
  3. It's very beneficial to use a password manager.
    • Have it generate random unique password for each account you use.
    • Password managers I recommend include 1Password, Bitwarden, and Proton Pass in no particular order. They're all great.

If you understood all that and get why I would make those recommendations: there is not going to be much else for you here. If some of that is confusing, counter intuitive or if it sounds Greek to you: please keep reading and I'll walk you through securing your online accounts in as plain language as I can muster.

|



   

Part 1. Picking a great password

A great password has three traits:

  1. It's practical - easy to type and remember.
  2. It's long - hard for computers to guess.
  3. It's private - only you know it.

In the web comic XKCD #936 the author gives us a great example of two kinds of passwords: the complex kind we've been taught to use and a simple one that's easy to remember and just a bit longer. In the comic (which admittedly is pretty full of nerd jargon) we're taught that the simpler password is is significantly more secure.

The examples given are:

Password Time to crack at 1000 guesses / second
Tr0ub4dor 3 days
correcthorsebatterystaple 550 years

Now realistically... unless you're some high level government official or Taylor Swift (Omg! Hi Taylor!): nobody is spending 3 days of computer power cracking your accounts. So why bother? For me it's simple: I'm fed up with bad passwords. I don't like typing a password like Tr0ub4dor using a TV remote or telling my house guests which 'A' in my WiFi password is really a '4'. Knowing that the easier password is about 67000x stronger makes it a no brainer.

Not to contradict the wisdom of XKCD, but... when you create a password for real you are probably going to want to include capital letters, symbols and numbers. This is just to be sure the password is not rejected by most password systems that demand your password have those criteria. The last thing we want is having to remember which site required symbols or capital letters and which ones didn't.

Keep it simple!

When adding capital letters, symbols and numbers: keep it simple! Adding 4 digits from your phone number or zip code will make it easier to remember.

Here's an example of a great password: Correct9-Horse0-Battery2-Staple1. It's easy to type, long enough to take centuries to crack, and... well, now Taylor Swift knows that one. Pick 4 words only you know and we're in great shape.

   

Change a couple passwords

I'm assuming you're starting from the same place as most folks:

Does that sound like you? I'm glad you're here.

This isn't your fault.

There's no shame in having an insecure password, having been hacked or re-using the same password for a long time.

It's only in recent years been getting easier for websites and apps to follow best practices and for users to authenticate securely. We are still a far cry away from security being even remotely fool-proof - it's not even especially techie-proof.

Here's what I suggest you do over the next few days or weeks:

  1. Come up with one great new password using the advice from the previous section.
  2. Change the password on your most important accounts (email, bank, payment, socials) to that password.
  3. Enable MFA (multi factor authentication) on all of those accounts as you go.

Making that change will already help you a lot in terms of security and peace of mind. If you're confused about MFA: don't worry - I'll cover that in the next section.

It might be surprising to hear me suggest using the same password for multiple accounts – you would be right to think that its not ideal. That said: this guide is for regular folks and regular folks don't have the tools, motivation, or patience to deal with dozens or hundreds of unique passwords. We will talk about how to make that easy in the upcoming section on password managers.

   

MFA: rule of 3

What the heck is MFA?

Every step you take to prove an account is yours is a factor. MFA (multi factor authentication) means having more than one factor such as requiring a password and providing a number texted to your phone.

There's a great rule of 3 to help you remember what makes a great multi factor authentication setup:

  1. Something you know - like a password or pin
  2. Something you have - like a smartphone. Authenticator apps generate a short code that refreshes every 30 seconds – if you've ever been asked to enter a 6-digit code from an app to sign in, that's called a TOTP. It's one of the best second factors you can use. USB security keys (small physical devices you plug in or tap) are an even stronger option, though most people don't need one for everyday use.
  3. Something you are - like a fingerprint or facial recognition

Any accounts you have that are secured with all of those factors are in great shape. That might not always be possible and may sometimes be undesirable, and that's okay sometimes too.

My advice is to use all 3 factors (if possible) for:



   

Part 2. Leveling up (use a password manager)

   

What is a password manager?

A password manager is an app that remembers passwords for you. Install it on your phone and computer, add its browser extension, and it fills in your passwords automatically every time you sign in somewhere.

The bigger benefit: it can generate a random unique password for every site you use. If one site gets hacked and your password leaks: the attacker only gets that one password. Every other account you own stays safe. This is the tool that makes “use a unique password per site” actually practical.

   

Which one

There are many options that are excellent choices but I'll give a quick overview of three I recommend: 1Password, Bitwarden, and Proton Pass. All three are reputable, well-supported, and widely used.

App Free tier Paid plan Notes
1Password No ~$5/month Very polished and widely trusted.
Bitwarden Yes ~$20/year Open source. Free tier covers most people.
Proton Pass Yes (limited) ~$2/month Newer but strong. Privacy-focused company. (My favorite)

I use Proton Pass and used 1Password for years before that - both are excellent. Bitwarden is a good pick if you want free or very cheap.

No lock-in

All three apps let you export your passwords as a file and import that file into any of the others. You are not committing to an ecosystem - you can switch at any time.

   

Quick aside – online shopping

I do a lot of online shopping and I try to support smaller creators when I can. That puts me in a pickle though: I'm creating lots of accounts and I expect small stores to know less about securing their databases.

That scenario raises a flag for me in terms of risk. Here are some options to mitigate that risk:

  • Say no when prompted to save payment details.
  • Pay with a third party app like Apple Pay so payment security is handled by a company that has expertise in securing payments.
  • Use a service like Privacy Card to generate a single-use credit card for that purchase.

   

Other options

The devices you use might have a password manager built in such as Apple or Google devices and browsers. In those cases having a built-in password manager might be more convenient for you and have all the features you'd need.

My reccomendation is still to use a dedicated reputible password manager that you can use on any device or browser but I don't think it's a bad thing to use Apple's or Google's password managers.

   

Getting started

  1. Download the app and install the browser extension it recommends.
  2. Create your account with a new passphrase – built the same way as before, but one you haven't used anywhere else. This is your one password to rule them all, so make it a good one.
  3. Import your existing accounts or let the app save them as you sign in to things – most apps walk you through this.
  4. Go through your most important accounts (email, bank, socials) and update each password to one the manager generates for you. This is the key step. From here on those accounts each have a unique password that nobody could guess – including you.
  5. From now on: whenever you create a new account anywhere, use the generator and let it save the result. You never have to think about it again.

You started with one password shared across everything. You now have a strong unique passphrase getting you into a manager that handles everything else. The only password you need to remember is the one that unlocks all the others.

That's a genuinely good place to be. 🌼

-xo

Back to top



xo © 2026 all rights reserved — attribution

Robots can go to hell.