I Used the Same Password for Ten Years and One Data Breach Changed Everything

My bank emailed me at 11 PM. “We detected unusual login activity.” Someone in another state was trying to access my account. They had my password. They had it because I used the same password for my bank, my email, a forum I joined in 2014, and a pizza delivery app. One of those got breached. Everything else was now open.

I changed every password that night. All seventy three of them. It took six hours. Do not be me. Here is the system I should have been using all along.

passwords, organization, password manager, security, unique
passwords, organization, password manager, security, unique

Use a Password Manager

Bitwarden is free. It syncs between your phone and computer. You remember one master password — make it long, make it something you have never used anywhere else. The password manager generates and stores all your other passwords. Random strings like “xK9#mP2vL7@qR4.” You do not type them. The manager fills them in automatically.

Apple users have iCloud Keychain built in. Chrome users have Google Password Manager. Both are fine for most people. The important part is using something that is not your brain. Your brain is bad at passwords.

The Master Password Rule

Your master password should be a passphrase, not a word. Four or five random words strung together — “correct-horse-battery-staple” — is harder for a computer to crack than “P@ssw0rd!23” and easier for you to remember. Length beats complexity every time. A twenty character sentence fragment is stronger than an eight character jumble of symbols.

Two-Factor Authentication on Everything

Email. Bank. Social media. Any account that offers it. An authenticator app is better than SMS codes because SIM swapping attacks can intercept text messages. Authy, Google Authenticator, or the one built into your password manager — pick one and use it. The five extra seconds it adds to logging in is worth never having to call your bank at 11 PM.

I now have unique passwords on every account and two factor authentication on the important ones. The next data breach that leaks my password for some random website will leak exactly one password. My bank will not care.

Quick Summary: Get a password manager (Bitwarden is free). One strong master passphrase. Unique passwords everywhere. Two factor authentication on email and banking. Auth app beats SMS. No more reused passwords.