Privacy › Module 2 › Lesson 1
Strong Passwords & Password Managers
Create strong, unique passwords and use a password manager the right way
Opening
Password123 is not a strategy
Reused passwords are the top reason one breach becomes ten. When attackers steal credentials from one site, they try the same email and password everywhere—banking, email, work SSO. Strong passwords are long, unique, and stored in a tool you can actually use daily.
1. What Makes a Password Strong?
Length beats complexity tricks
A 16+ character passphrase like correct-horse-battery-staple-river is stronger than P@ssw0rd! and easier to generate randomly with a manager.
Unique per account
Never reuse banking, email, and social passwords. One leak should not unlock your whole life.
Not based on public info
Avoid birthdays, pet names, usernames, or keyboard patterns like qwerty123.
2. Use a Password Manager
Password managers generate and store unique passwords behind one strong master password plus device security (PIN, biometrics, or security key). Reputable options include Bitwarden, 1Password, and built-in browser vaults with a strong master secret. You only memorize one master password. The manager fills login forms and warns about reused or breached passwords.
3. Passkeys — The Next Step
Passkeys use cryptographic keys tied to your device instead of a memorized password. They resist phishing because there is no password to type on a fake site. Enable passkeys on major accounts when offered—they work alongside passwords during the transition.
Check breach status safely
Services like haveibeenpwned.com let you check if an email appeared in known breaches. Never paste your actual password into random websites—only use trusted breach-check tools.
Knowledge Check
The biggest risk of reusing passwords is:
Multiple choice
Knowledge Check
A password manager helps you:
Multiple choice
Knowledge Check
True or False: Long random passphrases are generally stronger than short complex passwords.
True or False