Why Passwords Get Compromised
The most common ways accounts get hacked are: reusing the same password across sites, using simple/guessable passwords, and falling for phishing attacks. Not sophisticated hacking.
What Makes a Strong Password
- At least 12 characters long (16+ is ideal)
- Mix of uppercase, lowercase, numbers, and symbols
- Not based on personal information (name, birthday, city)
- Not a dictionary word or common phrase
- Unique — not used on any other account
Easy strong password technique: Take a sentence you'll remember: "My cat Mango loves to sleep at 3am!" → McMl2sl@3am! — 12 characters, easy to remember, hard to crack.
Use a Password Manager
The best practice is to use a password manager — it generates and stores unique complex passwords for every site. You only need to remember one master password.
- Free options: Bitwarden (open source), KeePass
- Paid options: 1Password, Dashlane
- Built-in: Google Password Manager, Apple Keychain (good for most users)
Two-Factor Authentication (2FA)
Enable 2FA on every important account. Even if your password is stolen, the attacker still can't log in without your second factor.
- Priority accounts for 2FA: email, banking, UPI, social media, government portals
- Authenticator apps (Google Authenticator, Authy) are safer than SMS 2FA
- Never share 2FA codes with anyone
Check if You've Been Breached
- Visit haveibeenpwned.com — enter your email to see if it appears in known data breaches
- If breached, change that password immediately on every site where you use it