This page goes over a few simple steps you can take today to improve the security of your online accounts. Here are the key takeaways:
Correct9-Horse0-Battery2-Staple1" over one
like "Tr0ub4dor".
If you understood all that and get why I would make those recommendations: there is not going to be much else for you here. If some of that is confusing, counter intuitive or if it sounds Greek to you: please keep reading and I'll walk you through securing your online accounts in as plain language as I can muster.
A great password has three traits:
In the web comic XKCD #936 the author gives us a great example of two kinds of passwords: the complex kind we've been taught to use and a simple one that's easy to remember and just a bit longer. In the comic (which admittedly is pretty full of nerd jargon) we're taught that the simpler password is is significantly more secure.
The examples given are:
| Password | Time to crack at 1000 guesses / second |
|---|---|
Tr0ub4dor | 3 days |
correcthorsebatterystaple | 550 years |
Now realistically... unless you're some high level government official or Taylor
Swift (Omg! Hi Taylor!): nobody is spending 3 days of computer power cracking
your accounts. So why bother? For me it's simple: I'm fed up with bad
passwords. I don't like typing a password like Tr0ub4dor using a TV remote or
telling my house guests which 'A' in my WiFi password is really a '4'.
Knowing that the easier password is about 67000x stronger makes it a no brainer.
Not to contradict the wisdom of XKCD, but... when you create a password for real you are probably going to want to include capital letters, symbols and numbers. This is just to be sure the password is not rejected by most password systems that demand your password have those criteria. The last thing we want is having to remember which site required symbols or capital letters and which ones didn't.
When adding capital letters, symbols and numbers: keep it simple! Adding 4 digits from your phone number or zip code will make it easier to remember.
Here's an example of a great password: Correct9-Horse0-Battery2-Staple1. It's
easy to type, long enough to take centuries to crack, and... well, now Taylor
Swift knows that one. Pick 4 words only you know and we're in great shape.
I'm assuming you're starting from the same place as most folks:
Tr0ub4dor&3).
123!!! at the end for example.)Does that sound like you? I'm glad you're here.
There's no shame in having an insecure password, having been hacked or re-using the same password for a long time.
It's only in recent years been getting easier for websites and apps to follow best practices and for users to authenticate securely. We are still a far cry away from security being even remotely fool-proof - it's not even especially techie-proof.
Here's what I suggest you do over the next few days or weeks:
Making that change will already help you a lot in terms of security and peace of mind. If you're confused about MFA: don't worry - I'll cover that in the next section.
It might be surprising to hear me suggest using the same password for multiple accounts – you would be right to think that its not ideal. That said: this guide is for regular folks and regular folks don't have the tools, motivation, or patience to deal with dozens or hundreds of unique passwords. We will talk about how to make that easy in the upcoming section on password managers.
Every step you take to prove an account is yours is a factor. MFA (multi factor authentication) means having more than one factor such as requiring a password and providing a number texted to your phone.
There's a great rule of 3 to help you remember what makes a great multi factor authentication setup:
Any accounts you have that are secured with all of those factors are in great shape. That might not always be possible and may sometimes be undesirable, and that's okay sometimes too.
My advice is to use all 3 factors (if possible) for:
A password manager is an app that remembers passwords for you. Install it on your phone and computer, add its browser extension, and it fills in your passwords automatically every time you sign in somewhere.
The bigger benefit: it can generate a random unique password for every site you use. If one site gets hacked and your password leaks: the attacker only gets that one password. Every other account you own stays safe. This is the tool that makes “use a unique password per site” actually practical.
There are many options that are excellent choices but I'll give a quick overview of three I recommend: 1Password, Bitwarden, and Proton Pass. All three are reputable, well-supported, and widely used.
| App | Free tier | Paid plan | Notes |
|---|---|---|---|
| 1Password | No | ~$5/month | Very polished and widely trusted. |
| Bitwarden | Yes | ~$20/year | Open source. Free tier covers most people. |
| Proton Pass | Yes (limited) | ~$2/month | Newer but strong. Privacy-focused company. (My favorite) |
I use Proton Pass and used 1Password for years before that - both are excellent. Bitwarden is a good pick if you want free or very cheap.
All three apps let you export your passwords as a file and import that file into any of the others. You are not committing to an ecosystem - you can switch at any time.
I do a lot of online shopping and I try to support smaller creators when I can. That puts me in a pickle though: I'm creating lots of accounts and I expect small stores to know less about securing their databases.
That scenario raises a flag for me in terms of risk. Here are some options to mitigate that risk:
The devices you use might have a password manager built in such as Apple or Google devices and browsers. In those cases having a built-in password manager might be more convenient for you and have all the features you'd need.
My reccomendation is still to use a dedicated reputible password manager that you can use on any device or browser but I don't think it's a bad thing to use Apple's or Google's password managers.
You started with one password shared across everything. You now have a strong unique passphrase getting you into a manager that handles everything else. The only password you need to remember is the one that unlocks all the others.
That's a genuinely good place to be. 🌼
-xo
xo © 2026 all rights reserved — attribution