FREEBeginner · 8 minute read

Long, unique passwords and safe recovery

Build account resilience with unique credentials, a password manager and a recovery plan.

WHAT YOU WILL LEARN

Learning objectives

  • Explain why reuse spreads compromise
  • Choose length and uniqueness over predictable substitutions
  • Protect password-manager and recovery access
01

Make each password independent

A password reused across services turns one breach into several account risks. Use a reputable password manager to generate and store a different credential for each account. Replacing letters with familiar symbols does not make a common phrase unpredictable. A memorable passphrase should be long and not based on public facts about you.

02

Protect the password manager

Use a strong, unique master credential and enable supported MFA. Keep devices updated and lock the vault when it is not needed. Understand how recovery works before an emergency. An exported vault can expose many accounts at once, so do not leave unprotected exports in Downloads, email or shared drives.

03

Plan for compromise

Change credentials when there is evidence of exposure, reuse or takeover. Secure the email account used for recovery, review active sessions and revoke suspicious access. Password changes alone may not end an attacker’s existing sessions or app permissions. Prefer passkeys or phishing-resistant MFA when supported.

APPLIED EXAMPLE

Put it in context

An employee receives a breach notice from an old shopping site. Their work account uses the same password. The useful action is to replace reused credentials, review sessions and enable MFA—not merely add an exclamation mark to every password.

Illustrative scenario for learning, not a claim about a verified customer incident.

Common mistakes

  • Reusing a memorable password
  • Treating a complexity checklist as proof of safety
  • Keeping unprotected vault exports

Your practical checklist

Checklist ticks are temporary and are not recorded as account progress.

MINI RECAP

Uniqueness limits the impact of a breach; length helps resist guessing; secure recovery keeps you in control.

Put your understanding to the test.

Further authoritative reading ↗