Why Passwords Get Compromised

The most common ways accounts get hacked are: reusing the same password across sites, using simple/guessable passwords, and falling for phishing attacks. Not sophisticated hacking.

What Makes a Strong Password

  • At least 12 characters long (16+ is ideal)
  • Mix of uppercase, lowercase, numbers, and symbols
  • Not based on personal information (name, birthday, city)
  • Not a dictionary word or common phrase
  • Unique — not used on any other account
Easy strong password technique: Take a sentence you'll remember: "My cat Mango loves to sleep at 3am!" → McMl2sl@3am! — 12 characters, easy to remember, hard to crack.

Use a Password Manager

The best practice is to use a password manager — it generates and stores unique complex passwords for every site. You only need to remember one master password.

  • Free options: Bitwarden (open source), KeePass
  • Paid options: 1Password, Dashlane
  • Built-in: Google Password Manager, Apple Keychain (good for most users)

Two-Factor Authentication (2FA)

Enable 2FA on every important account. Even if your password is stolen, the attacker still can't log in without your second factor.

  • Priority accounts for 2FA: email, banking, UPI, social media, government portals
  • Authenticator apps (Google Authenticator, Authy) are safer than SMS 2FA
  • Never share 2FA codes with anyone

Check if You've Been Breached

  • Visit haveibeenpwned.com — enter your email to see if it appears in known data breaches
  • If breached, change that password immediately on every site where you use it