Passwords, MFA and Password ManagersUpdated: 2026
Create strong passwords, use a manager, and enable MFA β the foundation of your digital security.
By the end of this module, you'll be able toβ¦
- Create strong, memorable passwords (passphrases)
- Understand why reusing a password is dangerous
- Set up and use a password manager
- Enable and use MFA (two-factor authentication)
- Understand passkeys and the future of authentication
Why passwords remain a major target
In 2024, a database containing 10 billion email/password combinations was published on a hacker forum. If your password is in it β and if you reuse it elsewhere β all your accounts are at risk.
81% of data breaches involve weak or reused passwords (Verizon 2024 report). Attackers don't need to "hack" your account β they simply try your email with passwords found on other sites.
The good news: a truly strong password, unique per account, combined with MFA, eliminates the vast majority of authentication-related risks.
The most common mistakes
β What most people do (and shouldn't)
- Using personal information: first name, birth date, pet's name
- Short passwords: "Abc123!" β 8 characters crack in seconds
- Reusing the same password everywhere: if one account is compromised, they all are
- Simple variants: "Password1!" β "Password2!" β "Password3!"
- Sharing passwords by email, text, or sticky note
- Using dictionary words: dictionary attacks test them in seconds
Creating a strong password β the passphrase
The most effective and memorable technique: the passphrase. Instead of a short complex word, use 4 to 6 combined random words.
Passphrase example:
Horse-Battery-Staple-Correct-27!
28 characters Β· 4 random words + digit + symbol Β· Thousands of years to crack
β Passphrase rules
- At least 16 characters (longer is better)
- 4 to 6 truly random words β not a known phrase
- Add a digit and a symbol for sites that require them
- Unique per account β never reuse
Brute-force and dictionary attacks
Brute force: the program tries every possible combination. An 8-character password with letters and digits: about 218 billion combinations β tested in a few hours by a modern computer.
Dictionary attack: the program tests common words, first names, dates, then their variants (password β P4ssword β P4ssword1). If your password resembles a real word, it will fall quickly.
Credential stuffing: attackers use databases of stolen passwords to try them on other sites. That's why reuse is so dangerous.
Password reuse β the most underestimated risk
A gaming forum is hacked. Your password "Gamer2019!" is stolen. The attacker tries it on your email (found on the forum). Your email uses the same password. Within 5 minutes, they access your email, can reset all your other accounts, and take over your digital life.
Just one hacked site, if you reuse the same password, endangers all your other accounts. The solution: a unique password per site β impossible to memorize without a manager.
Using a password manager
A password manager generates and stores unique, complex passwords for each site. You only need to remember one master password β the manager does the rest.
β Recommended managers (free/freemium)
- Bitwarden: open source, free, multi-device sync
- 1Password: excellent UX, paid but very complete
- Dashlane: free tier available, intuitive interface
- KeePass: 100% local, open source, for advanced users
Chrome, Firefox and Safari offer built-in managers. It's better than nothing, but a dedicated manager offers more features and isn't tied to a single browser.
Understanding MFA / 2FA
MFA (multi-factor authentication) adds a second check after your password. Even if an attacker has your password, they can't access your account without this second factor.
Authenticator (Google, Microsoft, Authy) β code that changes every 30s
Code received by text β convenient but vulnerable to SIM swapping
YubiKey β the most secure, phishing-resistant
β Enable MFA as a priority on
- Your main email (the gateway to all your other accounts)
- Your banking and financial accounts
- Your password manager
- Your professional social networks (LinkedIn)
MFA's limits and MFA fatigue
An attacker has Thomas's password. He repeatedly tries to log in, sending dozens of MFA approval requests to Thomas's phone. Exhausted, Thomas eventually approves one just to make the notifications stop. The attacker is in.
MFA fatigue (or push bombing) means bombarding the user with approval notifications until they give in out of exasperation. This is a real attack that has compromised several major companies.
β Protecting against MFA fatigue
- Never approve an MFA request you didn't initiate
- If you get unexpected MFA notifications: change your password immediately
- Prefer OTP apps (6-digit codes) over push notifications for critical accounts
Discovering passkeys
Passkeys are the next generation of authentication. They replace the password with a cryptographic key stored on your device, unlocked by your fingerprint, your face, or a local PIN.
β Advantages of passkeys
- Impossible to phish β the key never leaves your device
- No password to remember or type
- Resistant to database leaks
- Supported by Google, Apple, Microsoft, GitHub, and a growing number of sites
Passkeys are still being rolled out gradually, but if a service offers them, enable them β it's safer AND more convenient than a password.
Securing your accounts for the long run
β 5-step action plan
- Step 1: Install a password manager (Bitwarden is free)
- Step 2: Change the passwords of your 5 most important accounts (email, bank, social) to unique passphrases
- Step 3: Enable MFA on your email and your manager first
- Step 4: Check if your emails have been compromised at haveibeenpwned.com
- Step 5: Gradually migrate the rest of your accounts to unique passwords
Password strength tester
Type a password to see its strength in real time. Nothing is sent anywhere β everything is calculated in your browser.
Module quiz
Test what you've learned with 4 questions.
See also