Security

How to Create Strong Passwords

Build strong unique passwords and protect them with a password manager and MFA.

Glowing cybersecurity shield protecting streams of data

Build strong unique passwords and protect them with a password manager and MFA. Start with the checks below and confirm the effect of each change before moving on.

Length and uniqueness matter

Use a different password for every important account. Long, randomly generated passwords resist guessing better than clever substitutions in short words.

Use a password manager

A reputable password manager can generate and store unique credentials. Protect its vault with a memorable long passphrase and multi-factor authentication.

Respond to a breach

Change reused or exposed passwords, sign out other sessions and review recovery details. If your phone behaves suspiciously, follow our phone security checklist.

Create a password system you can maintain

Prioritize email, banking, cloud storage, social accounts and the password manager itself. Give every account a different randomly generated password. Uniqueness limits the damage when one service is breached; an attacker cannot reuse the exposed credential elsewhere. Length matters more than predictable substitutions such as replacing “a” with “@”.

Set up a password manager safely

  1. Choose a reputable manager with clear security documentation and recovery options.
  2. Create a long master passphrase that you have never used elsewhere.
  3. Enable multi-factor authentication and securely store its recovery code.
  4. Import or add accounts, then replace reused passwords one at a time.
  5. Export an encrypted backup only if you understand how it will be protected and updated.

Do not store the master password in the same vault it unlocks. Make sure a trusted recovery plan exists before deleting old records.

Respond to breach alerts

Open the affected service directly instead of clicking an alert link. Change the exposed password, sign out other sessions, check recovery email and phone details, and inspect recent activity. Change any other account that reused that credential. MFA reduces risk, but it does not make phishing harmless: never approve an unexpected login prompt or share a one-time code. Passkeys can offer stronger phishing resistance when a service and your devices support them. Keep recovery methods current so stronger security does not lock you out.