Passwords and Account Security
Password Managers, Passkeys and Two-Step Verification
Passwords have a bad reputation, but a few simple changes make your accounts much harder to take over. This guide explains what to do, in plain English and without the jargon.
Technology & Digital Life
↓
Chapter I
Why Passwords Fail
How Accounts Really Get Taken Over
For years, people were told to create passwords full of capital letters, numbers and symbols, and to change them every few months. Many followed this advice and still had their accounts stolen. Understanding how accounts are actually compromised shows why.
Criminals rarely guess passwords one at a time. More often, they obtain huge lists of email addresses and passwords stolen from data breaches at other websites and try them across many services, a technique called credential stuffing. If you use the same password in several places, a breach at one small website can unlock your email, your shopping and your bank. Others use phishing, which tricks you into typing your password into a fake page, or malware that records what you type.
This is why the most important rule is that every important account should have its own unique password. A password that is complex but reused is far weaker than one that is simple but unique. The second rule is to add a second check, so that a stolen password is not enough on its own. The third is to protect the account that controls the others, which is usually your email, because password reset links are sent there.
A password protects far more than an account. Your email can unlock almost everything else you own online.
· · ·
"A password protects far more than an account. Your email can unlock almost everything else you own online."
Chapter II
Creating Strong Passwords
Three Random Words and Other Sensible Rules
The current advice from the National Cyber Security Centre is different from older guidance, and it is easier to follow.
For passwords that you need to remember, such as the one for your password manager, your device and your email, use three random words, combined into a phrase. Length matters more than complexity. A password such as a string of three unrelated words is long, hard for a computer to guess and easy to remember. Choose words that are unusual and not connected to you, and avoid famous phrases, song lyrics and names of family members, pets or places that others can find out. You can add numbers or a symbol if a site insists, but the length is what protects you.
Avoid common patterns. Passwords such as Password1, a football team, a birthday or a keyboard pattern like qwerty are among the first that attackers try. Do not make small changes to an old password, such as adding a number at the end, as attackers anticipate these.
Contrary to old advice, you do not need to change your passwords regularly unless you have reason to think that they have been compromised. Forced regular changes tend to make people choose weaker, more predictable passwords. Change a password when a service tells you that it has been breached, when you suspect that someone knows it or when you have shared it.
Security Questions
Questions such as your mother's maiden name or your first school are weak, because the answers can often be found online. Where a service asks them, you can enter a random answer and store it in your password manager.
· · ·
Chapter III
Password Managers
Letting Software Do the Remembering
Nobody can remember dozens of unique, strong passwords. A password manager is a program that does the remembering for you, and it is one of the best security tools that an ordinary person can use.
A password manager stores all your passwords in an encrypted vault, locked by a single strong master password. It can generate long, random passwords for each new account, fill them in automatically on the correct website and warn you if a password has been reused or has appeared in a breach. Because it fills in passwords only on the genuine site, it can also help to protect you from phishing, since it will not recognise a fake one.
Choose a reputable manager. The NCSC states that using a password manager is generally safer than reusing passwords or writing them in an insecure place. Options include standalone products from established companies and the managers built in to Apple, Google and Microsoft's systems and browsers, which are free and perfectly acceptable for many people. Look for a manager that is regularly updated, has a good reputation and offers two-step verification for the vault itself.
To start, set up the manager, create a strong master password, and add your most important accounts first: email, banking, shopping and social media. Over a few weeks, replace weak and reused passwords with generated ones. It is vital to remember your master password and to set up the recovery options carefully, since a forgotten master password may mean that you lose access to the vault.
· · ·
"The best password is the one you never have to remember, because a manager creates it and a second check protects it."
Chapter IV
Two-Step Verification and Passkeys
Adding a Second Lock
Two-step verification, sometimes called two-factor authentication or 2FA, is the single most effective thing you can do for an important account. It means that a password alone is not enough to get in.
When you sign in, the service asks for a second proof that it is really you. This might be a code sent by text message, a code generated by an authenticator app, a prompt on your phone or a physical security key. If a criminal obtains your password, they still cannot sign in without the second step. Text message codes are better than nothing but can be intercepted or diverted by criminals who persuade a mobile provider to transfer your number, so authenticator apps and security keys are stronger. Whichever method you use, switch it on for email, banking, social media, shopping and cloud storage accounts.
Be aware of attempts to trick you into sharing a code. Genuine services will never phone or message you to ask for the code that they have sent to you. Criminals pose as banks or companies and ask for it so that they can complete a login or a payment. If someone asks for a one-time code, it is a scam.
Passkeys are a newer technology that replaces passwords with a cryptographic key stored on your device and unlocked by your fingerprint, face or device PIN. They are resistant to phishing, because they work only on the genuine website, and they are easier to use. Many major services now support them, and they are managed by your phone, computer or password manager. They are likely to become more common, and are worth using where they are offered.
· · ·
Chapter V
Protecting What Matters Most
Prioritising Your Accounts
You do not need to secure every account to the highest standard on the first day. Start with the ones that would cause the most harm if they were taken over.
Your email account comes first, because it is the key to resetting other passwords. Next come banking and financial accounts, then online shopping accounts that store card details, cloud storage that holds your photographs and documents, social media accounts that others could use to impersonate you, and your mobile phone account, since criminals can use it to intercept codes. For each, use a unique password from your manager, switch on two-step verification and check the recovery options.
Recovery options are a frequent weakness. Check that the recovery email address and phone number on each account are yours and up to date. Review which devices and apps are signed in, and remove any that you do not recognise. Be careful about signing in with a social media account on other sites, since a compromise of one affects the others.
Think about sharing. Avoid sharing passwords with others, even family, and use the sharing features that services provide where they exist, such as family plans and delegated access. For partners and families, agree how important accounts will be accessed in an emergency, and consider the emergency access feature in some password managers.
Check Your Exposure
Use a breach checking service such as Have I Been Pwned to see whether your email addresses have appeared in breaches, and change passwords for any affected services.
· · ·
Chapter VI
Making It Stick and Planning Ahead
Habits, Recovery and Digital Legacy
Good account security is built over weeks, and then it largely looks after itself. The key is to make the secure option the easy option.
Move in stages. Spend an hour on your email and your password manager. The next week, work through your banking and shopping accounts. In following weeks, deal with social media and the rest. Each time you sign in to an old account, update the password using your manager. Switch on automatic fill, so that the secure way is also the convenient way.
Plan for problems. Keep a copy of your password manager's recovery information, such as an emergency kit or a recovery key, in a safe place at home, not on the same device. Know what to do if a phone is lost or stolen, since your authenticator app may be on it. Many apps allow you to back up or transfer your codes, and services provide backup codes that you can print and keep safely.
Think about what happens if you die or lose capacity. Loved ones may need to access your accounts, to close them or to find important documents. Some services, such as Apple and Google, allow you to nominate a legacy contact or an inactive account manager. Leave clear instructions, perhaps with your will or a trusted person, about how your password manager and key accounts can be accessed. Do not write passwords in a will, which becomes public once probate is granted.
A Short Checklist
One unique password for every important account. A password manager. Two-step verification on email, banking and social media. A recovery plan. A legacy plan.
· · ·
We try to respond to all messages within 48 working hours, please be patient, we will get back to you.
Your cookie preferences
We use cookies to keep the site working, to understand how it is used and, with your permission, to show embedded video. Accept all, reject everything that is not strictly necessary, or choose your own settings. Read our policies for more detail.
Cookie preferences
Choose which cookies you are happy for us to use. Strictly necessary cookies are always active because the site cannot work without them. Your choices are stored for 30 days and you can change them at any time using the cookie settings link in the footer. See our policies for more detail.
Always on
Strictly necessary cookies allow core website functionality such as user login and account management. The website cannot be used properly without strictly necessary cookies.
Name
Provider / domain
Expiry
Purpose
PHPSESSID
PHP.netjwbiz.co.uk
Session
General purpose identifier used to maintain user session variables. Normally a randomly generated number.
mf_has_cookie
jwbiz.co.uk
1 day
Used to indicate whether the user's browser supports cookies.
mc_cookie_consent
jwbiz.co.uk
30 days
Stores your cookie consent preferences. Required for the cookie banner to work correctly.
browserupdateorg
jwbiz.co.uk
7 days
Used to track if a user has been shown a message suggesting they update their web browser.
Performance cookies are used to see how visitors use the website, e.g. analytics cookies. Those cookies cannot be used to directly identify a certain visitor.
Name
Provider / domain
Expiry
Purpose
is_unique
StatCounter Ltd.statcounter.com
1 year 1 month
Determines whether you are a first-time or returning visitor.
is_visitor_unique
StatCounter.statcounter.com
1 year 1 month
Assigns a unique visitor ID to track navigation and interaction for statistical purposes.
Targeting cookies are used to identify visitors between different websites, e.g. content partners, banner networks. Those cookies may be used by companies to build a profile of visitor interests or show relevant ads on other websites.
Name
Provider / domain
Expiry
Purpose
VISITOR_INFO1_LIVE
Google LLC.youtube.com
6 months
Set by YouTube to keep track of user preferences for embedded videos and to determine whether the visitor is using the new or old YouTube interface.
YSC
Google LLC.youtube.com
Session
Set by YouTube to track views of embedded videos.
Functionality cookies are used to remember visitor information on the website, e.g. language, timezone, enhanced content.
Name
Provider / domain
Expiry
Purpose
sc_is_visitor_unique
StatCounter Ltd.jwbiz.co.uk
1 year 1 month
Used to store number of visits.
Unclassified cookies are cookies that do not belong to any other category or are in the process of categorisation.