Passwords and Account Security Password Managers, Passkeys and Two-Step Verification

Passwords have a bad reputation, but a few simple changes make your accounts much harder to take over. This guide explains what to do, in plain English and without the jargon.

Technology & Digital Life

↓
Chapter I

Why Passwords Fail How Accounts Really Get Taken Over

For years, people were told to create passwords full of capital letters, numbers and symbols, and to change them every few months. Many followed this advice and still had their accounts stolen. Understanding how accounts are actually compromised shows why.

Criminals rarely guess passwords one at a time. More often, they obtain huge lists of email addresses and passwords stolen from data breaches at other websites and try them across many services, a technique called credential stuffing. If you use the same password in several places, a breach at one small website can unlock your email, your shopping and your bank. Others use phishing, which tricks you into typing your password into a fake page, or malware that records what you type.

This is why the most important rule is that every important account should have its own unique password. A password that is complex but reused is far weaker than one that is simple but unique. The second rule is to add a second check, so that a stolen password is not enough on its own. The third is to protect the account that controls the others, which is usually your email, because password reset links are sent there.

A password protects far more than an account. Your email can unlock almost everything else you own online.

· · ·
Chapter II

Creating Strong Passwords Three Random Words and Other Sensible Rules

The current advice from the National Cyber Security Centre is different from older guidance, and it is easier to follow.

For passwords that you need to remember, such as the one for your password manager, your device and your email, use three random words, combined into a phrase. Length matters more than complexity. A password such as a string of three unrelated words is long, hard for a computer to guess and easy to remember. Choose words that are unusual and not connected to you, and avoid famous phrases, song lyrics and names of family members, pets or places that others can find out. You can add numbers or a symbol if a site insists, but the length is what protects you.

Avoid common patterns. Passwords such as Password1, a football team, a birthday or a keyboard pattern like qwerty are among the first that attackers try. Do not make small changes to an old password, such as adding a number at the end, as attackers anticipate these.

Contrary to old advice, you do not need to change your passwords regularly unless you have reason to think that they have been compromised. Forced regular changes tend to make people choose weaker, more predictable passwords. Change a password when a service tells you that it has been breached, when you suspect that someone knows it or when you have shared it.

Security Questions

Questions such as your mother's maiden name or your first school are weak, because the answers can often be found online. Where a service asks them, you can enter a random answer and store it in your password manager.

· · ·
Chapter III

Password Managers Letting Software Do the Remembering

Nobody can remember dozens of unique, strong passwords. A password manager is a program that does the remembering for you, and it is one of the best security tools that an ordinary person can use.

A password manager stores all your passwords in an encrypted vault, locked by a single strong master password. It can generate long, random passwords for each new account, fill them in automatically on the correct website and warn you if a password has been reused or has appeared in a breach. Because it fills in passwords only on the genuine site, it can also help to protect you from phishing, since it will not recognise a fake one.

Choose a reputable manager. The NCSC states that using a password manager is generally safer than reusing passwords or writing them in an insecure place. Options include standalone products from established companies and the managers built in to Apple, Google and Microsoft's systems and browsers, which are free and perfectly acceptable for many people. Look for a manager that is regularly updated, has a good reputation and offers two-step verification for the vault itself.

To start, set up the manager, create a strong master password, and add your most important accounts first: email, banking, shopping and social media. Over a few weeks, replace weak and reused passwords with generated ones. It is vital to remember your master password and to set up the recovery options carefully, since a forgotten master password may mean that you lose access to the vault.

· · ·
Chapter IV

Two-Step Verification and Passkeys Adding a Second Lock

Two-step verification, sometimes called two-factor authentication or 2FA, is the single most effective thing you can do for an important account. It means that a password alone is not enough to get in.

When you sign in, the service asks for a second proof that it is really you. This might be a code sent by text message, a code generated by an authenticator app, a prompt on your phone or a physical security key. If a criminal obtains your password, they still cannot sign in without the second step. Text message codes are better than nothing but can be intercepted or diverted by criminals who persuade a mobile provider to transfer your number, so authenticator apps and security keys are stronger. Whichever method you use, switch it on for email, banking, social media, shopping and cloud storage accounts.

Be aware of attempts to trick you into sharing a code. Genuine services will never phone or message you to ask for the code that they have sent to you. Criminals pose as banks or companies and ask for it so that they can complete a login or a payment. If someone asks for a one-time code, it is a scam.

Passkeys are a newer technology that replaces passwords with a cryptographic key stored on your device and unlocked by your fingerprint, face or device PIN. They are resistant to phishing, because they work only on the genuine website, and they are easier to use. Many major services now support them, and they are managed by your phone, computer or password manager. They are likely to become more common, and are worth using where they are offered.

· · ·
Chapter V

Protecting What Matters Most Prioritising Your Accounts

You do not need to secure every account to the highest standard on the first day. Start with the ones that would cause the most harm if they were taken over.

Your email account comes first, because it is the key to resetting other passwords. Next come banking and financial accounts, then online shopping accounts that store card details, cloud storage that holds your photographs and documents, social media accounts that others could use to impersonate you, and your mobile phone account, since criminals can use it to intercept codes. For each, use a unique password from your manager, switch on two-step verification and check the recovery options.

Recovery options are a frequent weakness. Check that the recovery email address and phone number on each account are yours and up to date. Review which devices and apps are signed in, and remove any that you do not recognise. Be careful about signing in with a social media account on other sites, since a compromise of one affects the others.

Think about sharing. Avoid sharing passwords with others, even family, and use the sharing features that services provide where they exist, such as family plans and delegated access. For partners and families, agree how important accounts will be accessed in an emergency, and consider the emergency access feature in some password managers.

Check Your Exposure

Use a breach checking service such as Have I Been Pwned to see whether your email addresses have appeared in breaches, and change passwords for any affected services.

· · ·
Chapter VI

Making It Stick and Planning Ahead Habits, Recovery and Digital Legacy

Good account security is built over weeks, and then it largely looks after itself. The key is to make the secure option the easy option.

Move in stages. Spend an hour on your email and your password manager. The next week, work through your banking and shopping accounts. In following weeks, deal with social media and the rest. Each time you sign in to an old account, update the password using your manager. Switch on automatic fill, so that the secure way is also the convenient way.

Plan for problems. Keep a copy of your password manager's recovery information, such as an emergency kit or a recovery key, in a safe place at home, not on the same device. Know what to do if a phone is lost or stolen, since your authenticator app may be on it. Many apps allow you to back up or transfer your codes, and services provide backup codes that you can print and keep safely.

Think about what happens if you die or lose capacity. Loved ones may need to access your accounts, to close them or to find important documents. Some services, such as Apple and Google, allow you to nominate a legacy contact or an inactive account manager. Leave clear instructions, perhaps with your will or a trusted person, about how your password manager and key accounts can be accessed. Do not write passwords in a will, which becomes public once probate is granted.

A Short Checklist

One unique password for every important account. A password manager. Two-step verification on email, banking and social media. A recovery plan. A legacy plan.

· · ·
Subscribe for Full Access