Scams and staying safe
Passwords that actually work, without driving you mad
Most password advice given to people over the last twenty years was wrong, and it made everybody’s life harder for no benefit. It is worth explaining what changed, because the modern advice is genuinely easier.
The old advice was wrong
You were told to use something like P@ssw0rd!23, and to change it every ninety days.
Both parts turned out to be counterproductive. Forcing symbols and regular changes made passwords hard for humans to remember and barely harder for computers to guess, so people coped in the obvious way: they picked one password, added a number on the end, and used it everywhere.
That last part is the actual danger, and it is worth being clear about why.
The real risk is reuse, not complexity
Here is how most accounts are actually broken into.
Some company you signed up to years ago gets hacked, and the attackers take a list of email addresses and passwords. That company may be a hobby forum you have entirely forgotten. Your password is now on a list.
The attackers then try that email and password combination on hundreds of other services: banks, email providers, shopping sites, government portals. This is automated and costs them nothing.
If you used that password anywhere else, those accounts are now open, and no amount of exclamation marks would have helped. The password was not guessed. It was taken from somewhere else and reused.
The single most valuable thing you can do is stop using the same password twice. It matters far more than how complicated any individual password is.
What a good password looks like now
Long beats complicated. Four unrelated words are stronger than a short string of symbols, and immeasurably easier to remember. Something like copper lantern beach quiet is a genuinely strong password.
Unrelated is the key word. Words from a phrase, a song lyric or a common saying are much weaker, because guessing software knows those. Pick words with no connection to each other.
Nothing personal. No family names, birthdays, pet names, street names or football teams. All of that is guessable by anybody who has seen your social media.
Different for every account. This is the important one.
But how do you remember dozens of them?
You do not. That is the honest answer, and it is why password managers exist.
A password manager is a program that stores all your passwords, locked behind one master password. You remember exactly one password. It remembers the rest, fills them in for you, and can generate new ones you never have to see.
Reasonable people are suspicious of this. “Isn’t putting them all in one place dangerous?”
It is a fair question, and the answer is that the alternative is worse. The realistic alternatives are reusing one password everywhere, or writing them on a pad beside the computer. A password manager is dramatically safer than the first and, for most households, safer than the second.
The contents are encrypted, meaning that even the company running it cannot read them. If they are broken into, the attackers get a pile of scrambled data they cannot use.
Ones worth looking at: Bitwarden is free and genuinely good. 1Password is excellent and costs a few dollars a month. Apple and Google both have one built in, which is fine and much better than nothing if you live entirely in one of those worlds.
On writing them down
Every technical person will tell you never to write down passwords. In your own home, I think the advice needs more nuance.
The threat to your accounts is somebody on the other side of the world running automated software. It is not, realistically, a burglar reading your notebook.
So if the genuine choice is between using Fluffy2019 on all thirty accounts or writing thirty different passwords in a notebook, the notebook is safer. Not ideal, but safer.
If you do write them down:
- Keep the book somewhere not obvious, and not stuck to the monitor
- Do not label which account each one belongs to, or use a shorthand only you follow
- Keep your email and banking passwords out of it entirely, and memorise those two
A password manager is still better. But do not let perfect advice push you into the worst option.
The three that matter most
If doing this for every account feels overwhelming, start with these three, in this order:
- Your email. Whoever controls your email can reset the password on nearly everything else you own. It is the master key.
- Your banking.
- myGov, because it connects to the tax office, Medicare and Centrelink.
Give those three long, unique passwords that appear nowhere else, and turn on two-factor authentication for each. That is most of the benefit for a fraction of the effort.
What about being told to change them regularly?
Do not bother, unless there is a reason.
Regular forced changes make people pick weaker passwords and shuffle a number on the end. Modern guidance, including from government security agencies, is to use a strong unique password and change it only when there is cause: a service you use was breached, you shared it, or something feels wrong.
If this feels like a lot
It usually takes about an hour to set up a password manager and move the important accounts into it, and after that it makes daily life easier rather than harder, because you stop being locked out of things.
If you would rather have somebody sit with you and get it done properly in one go, that is a very common request and exactly the kind of session I do.