5 min

Passwords, Accounts & Multi-Factor Authentication

By the end of this module you'll understand why using the same password in several places is risky, how a password manager lets you keep a different strong password everywhere, and why a second sign-in step protects an account even if a password gets out.

One reused password can unlock more than one account

Passwords and accounts

One reused password can unlock more than one account.

When the same password is used in several places, someone who obtains it from one account may try it on your email, shopping, banking, and other accounts.

02

Why reused passwords create risk

The risk is mostly about what can happen quietly afterward — not that any one account is certain to be affected.

How a reused password can spread

  1. Step 1
    One website is compromised

    Imagine an online shop you signed up for a while ago is broken into, and its stored passwords get out.

  2. Step 2
    A reused password becomes known

    If you used that same password somewhere else, it is now a password that someone else has.

  3. Step 3
    The same details are tried elsewhere

    The matching email address and password are quietly tried on other sites — email, banking, and shopping among them.

  4. Step 4
    Other accounts may open

    Any account using that same password may open. Not all of them will — the ones that share the password are the ones at risk.

Learn more: small changes are not a different password

Using one base password with a small change on the end — the site’s name, a year, or an extra number — is a familiar pattern, and it is easy to work through automatically. A genuinely different password for each account is what keeps one leak from reaching the others.

03

Strong, unique passwords — and a manager to remember them

A different, strong password for every important account is the goal. A password manager is what makes that realistic.

What makes a password strong

  • Long

    Aim for at least 14 to 16 characters. Several unrelated words strung together works well and is easy to type.

  • Different everywhere

    A different password for every account, so one leak can never open a second place.

  • Not based on you

    Avoid names, birthdays, pets, and addresses — details that can be found or guessed.

The practical answer

A password manager creates these passwords, remembers them, and fills them in — so you only memorize one.

Learn more: is putting all my passwords in one place risky?

It is a fair question. The realistic comparison is not “a password manager versus a perfect memory” — it is “a manager versus reusing a few passwords everywhere, or keeping them in a notes file.” A reputable manager keeps everything encrypted, cannot read your passwords itself, and removes the reuse problem. It also only offers a saved password on the exact site it belongs to, so it quietly helps you avoid look-alike pages. Protect it with one long main password and turn on a second step for the manager itself.

04

Add a second sign-in step

A second step — sometimes called two-factor or MFA — means signing in takes something beyond your password.

Your password is something you know. A second step is something you have — usually a tap or a short code from your phone. Someone who steals only your password is then still missing a piece, so it cannot be used on its own.

Common second steps

  • Authenticator application
  • Security key
  • Passkey
  • Text-message code

The highest-value habit

Turn a second step on for your email first — it is the account used to reset the others.

Learn more: which second step is strongest?

Any second step is far better than none. A text-message code is good; an app on your phone that generates a rotating code or asks you to approve a sign-in is stronger; and a passkey or a small physical security key is strongest of all. Text-message codes are the weakest of these because a phone number can sometimes be moved to another device or a code can be read from a lock screen — but if a service only offers text codes, turn them on anyway.

Important: a second step is a strong lock, not a guarantee

Turning on a second step blocks the large majority of password-based break-ins, and it is one of the highest-value things you can do. It is not absolute, though — someone might still try to talk you into reading a code aloud or approving a prompt out of habit. If you ever get an approval request you did not start, do not approve it, and change that account’s password.

05

Staying able to get in

A second step only helps if you can still sign in after you lose or replace your phone. A few minutes of setup now saves a lot of stress later.

Three things worth setting up

  1. Step 1
    Save your backup codes

    Most services give you one-time codes when you turn on a second step. Keep them somewhere safe, like your password manager or a locked drawer.

  2. Step 2
    Check your recovery contacts

    Make sure the recovery email and phone number on your important accounts are ones you still control.

  3. Step 3
    Plan for a new phone

    If you use an app for your second step, check whether it can be moved or restored before you replace the device.

Keep it balanced

Account security should keep other people out without locking you out.

Learn more: recovery is a door too

Account recovery exists so you can get back in — which means it can also be a way for someone else to get in. Keep recovery answers unguessable (a password manager can store made-up ones), remove old phone numbers and email addresses you no longer use, and treat backup codes with the same care as passwords.

What to remember

Three ideas worth carrying forward

  • Using the same password in several places means one leak can open all of them — a different password for each keeps a problem contained.
  • A password manager is what makes long, unique passwords realistic, because you only have to remember one.
  • A second sign-in step makes a stolen password much less useful — and an app or security key is stronger than a text-message code.

Terms used in this module

Select a term to read its definition without leaving this page.

Finished this module?

Mark it complete to save your progress, or continue without marking it complete.