Passwords and multi-factor authentication
Reduce account risk with practical authentication habits that do not depend on memory alone.
Unique credentials#
Password reuse allows one service breach to endanger other accounts. Use a unique, sufficiently long password or passphrase for each important service. Avoid predictable substitutions and personal facts.
Password managers#
A reputable password manager can generate and store unique credentials, reducing the need to memorize many passwords. Protect the manager with a strong master credential and available MFA.
Multi-factor authentication#
MFA combines different evidence, such as something you know and something you possess. An authenticator app or security key generally resists more attacks than a password alone.
MFA does not make every login prompt safe. A convincing phishing site may still capture codes or trick a user into approving a request.
Recovery#
Keep recovery codes in a secure separate location. Maintain current recovery email or phone information, and review signed-in sessions after suspicious activity.
Common mistakes#
Do not share one-time codes with someone who contacts you. Do not approve an unexpected sign-in prompt. Security questions based on public facts can be weak recovery controls.
Priority order#
Start with email, financial, work, and password-manager accounts because they can unlock other services. Unique credentials plus MFA and protected recovery provide strong practical improvement.
Key points
- Every important account should use a unique password or passphrase.
- A password manager can generate and store strong credentials.
- MFA adds a separate factor but does not remove phishing risk.
- Recovery codes and contact details need secure, current storage.