Passwords and two-step verification
The password to your email can open most of your other accounts, because that is where reset links are sent. This lesson shows how to protect it properly.
Length beats cleverness
A long password made of several unrelated words is stronger and easier to remember than a short one full of symbols. Aim for a passphrase of 14 characters or more, such as four random words. Avoid song lyrics, names and dates, which attackers try first.
One password per account
When a company is breached, attackers try the leaked email and password on other sites. If you reuse a password, one breach opens every account that shares it. Give each account its own.
Let a password manager remember them
Nobody can remember dozens of long, different passwords. A password manager, whether the one built into your phone or browser or a dedicated app, creates and stores them for you, so you only have to remember one strong passphrase.
Add a second step
Two-step verification asks for something more than the password, such as a code from an authenticator app or a passkey. Turn it on for your email, your bank and your password manager first. An authenticator app or a passkey is stronger than a code sent by text message, but a text code is still better than nothing.