Module 04 / 15
πŸ”‘

Passwords, MFA and Password ManagersUpdated: 2026

Create strong passwords, use a manager, and enable MFA β€” the foundation of your digital security.

⏱️ ~25 min
πŸ“š 10 lessons
🎯 Beginner
🎯 Module objective

By the end of this module, you'll be able to…

  • Create strong, memorable passwords (passphrases)
  • Understand why reusing a password is dangerous
  • Set up and use a password manager
  • Enable and use MFA (two-factor authentication)
  • Understand passkeys and the future of authentication
1

Why passwords remain a major target

Scenario

In 2024, a database containing 10 billion email/password combinations was published on a hacker forum. If your password is in it β€” and if you reuse it elsewhere β€” all your accounts are at risk.

81% of data breaches involve weak or reused passwords (Verizon 2024 report). Attackers don't need to "hack" your account β€” they simply try your email with passwords found on other sites.

The good news: a truly strong password, unique per account, combined with MFA, eliminates the vast majority of authentication-related risks.

2

The most common mistakes

βœ— What most people do (and shouldn't)

  • Using personal information: first name, birth date, pet's name
  • Short passwords: "Abc123!" β€” 8 characters crack in seconds
  • Reusing the same password everywhere: if one account is compromised, they all are
  • Simple variants: "Password1!" β†’ "Password2!" β†’ "Password3!"
  • Sharing passwords by email, text, or sticky note
  • Using dictionary words: dictionary attacks test them in seconds
3

Creating a strong password β€” the passphrase

The most effective and memorable technique: the passphrase. Instead of a short complex word, use 4 to 6 combined random words.

Passphrase example:

Horse-Battery-Staple-Correct-27!

28 characters Β· 4 random words + digit + symbol Β· Thousands of years to crack

βœ“ Passphrase rules

  • At least 16 characters (longer is better)
  • 4 to 6 truly random words β€” not a known phrase
  • Add a digit and a symbol for sites that require them
  • Unique per account β€” never reuse
Key takeaway"Long and random beats short and complex. A 20-character phrase is infinitely safer than 'P@ssw0rd!'."
4

Brute-force and dictionary attacks

Brute force: the program tries every possible combination. An 8-character password with letters and digits: about 218 billion combinations β€” tested in a few hours by a modern computer.

Dictionary attack: the program tests common words, first names, dates, then their variants (password β†’ P4ssword β†’ P4ssword1). If your password resembles a real word, it will fall quickly.

Credential stuffing: attackers use databases of stolen passwords to try them on other sites. That's why reuse is so dangerous.

5

Password reuse β€” the most underestimated risk

Scenario

A gaming forum is hacked. Your password "Gamer2019!" is stolen. The attacker tries it on your email (found on the forum). Your email uses the same password. Within 5 minutes, they access your email, can reset all your other accounts, and take over your digital life.

Just one hacked site, if you reuse the same password, endangers all your other accounts. The solution: a unique password per site β€” impossible to memorize without a manager.

6

Using a password manager

A password manager generates and stores unique, complex passwords for each site. You only need to remember one master password β€” the manager does the rest.

βœ“ Recommended managers (free/freemium)

  • Bitwarden: open source, free, multi-device sync
  • 1Password: excellent UX, paid but very complete
  • Dashlane: free tier available, intuitive interface
  • KeePass: 100% local, open source, for advanced users
ℹ️
Is the browser's built-in manager enough?

Chrome, Firefox and Safari offer built-in managers. It's better than nothing, but a dedicated manager offers more features and isn't tied to a single browser.

Key takeaway"One strong, unique password per account. No human can memorize them all β€” that's why managers exist."
7

Understanding MFA / 2FA

MFA (multi-factor authentication) adds a second check after your password. Even if an attacker has your password, they can't access your account without this second factor.

πŸ“±
OTP app

Authenticator (Google, Microsoft, Authy) β€” code that changes every 30s

πŸ’¬
SMS (less safe)

Code received by text β€” convenient but vulnerable to SIM swapping

πŸ”
Physical key (FIDO2)

YubiKey β€” the most secure, phishing-resistant

βœ“ Enable MFA as a priority on

  • Your main email (the gateway to all your other accounts)
  • Your banking and financial accounts
  • Your password manager
  • Your professional social networks (LinkedIn)
8

MFA's limits and MFA fatigue

Scenario

An attacker has Thomas's password. He repeatedly tries to log in, sending dozens of MFA approval requests to Thomas's phone. Exhausted, Thomas eventually approves one just to make the notifications stop. The attacker is in.

MFA fatigue (or push bombing) means bombarding the user with approval notifications until they give in out of exasperation. This is a real attack that has compromised several major companies.

βœ“ Protecting against MFA fatigue

  • Never approve an MFA request you didn't initiate
  • If you get unexpected MFA notifications: change your password immediately
  • Prefer OTP apps (6-digit codes) over push notifications for critical accounts
9

Discovering passkeys

Passkeys are the next generation of authentication. They replace the password with a cryptographic key stored on your device, unlocked by your fingerprint, your face, or a local PIN.

βœ“ Advantages of passkeys

  • Impossible to phish β€” the key never leaves your device
  • No password to remember or type
  • Resistant to database leaks
  • Supported by Google, Apple, Microsoft, GitHub, and a growing number of sites

Passkeys are still being rolled out gradually, but if a service offers them, enable them β€” it's safer AND more convenient than a password.

10

Securing your accounts for the long run

βœ“ 5-step action plan

  • Step 1: Install a password manager (Bitwarden is free)
  • Step 2: Change the passwords of your 5 most important accounts (email, bank, social) to unique passphrases
  • Step 3: Enable MFA on your email and your manager first
  • Step 4: Check if your emails have been compromised at haveibeenpwned.com
  • Step 5: Gradually migrate the rest of your accounts to unique passwords
Key takeaway"Strong + unique password + MFA = 99% of attacks blocked. It's not complicated, it's a habit to build."
Interactive demo

Password strength tester

Type a password to see its strength in real time. Nothing is sent anywhere β€” everything is calculated in your browser.

12+ characters
Uppercase
Lowercase
Digit
Symbol
Not common
Estimated time to crack: β€”
Try: "password" β†’ very weak | "P4ssword!" β†’ medium | "Horse-Battery-Correct-2024!" β†’ excellent

Module quiz

Test what you've learned with 4 questions.

See also