Password Hygiene
Good account security combines unique passwords, safer sign-in methods, and recovery habits.
What you’ll learn
- Explain why reused passwords create risk.
- Use a password manager and multifactor authentication.
- Choose safer recovery and sharing habits.
Long, random, unique
Use a different password for every account. Aim for at least 16 characters where supported; a password manager can generate random passwords. A long passphrase made of randomly selected unrelated words is another option. Names, birthdays, sports teams, and predictable substitutions such as a→@ make weak choices.
Why reuse is dangerous
When a service is breached, attackers may try stolen credentials on other services. This is called credential stuffing. One unique password per account limits that chain reaction. Do not copy the example passwords shown on a lesson page.
Add another layer
Turn on multifactor authentication (MFA). Security keys and passkeys can provide phishing-resistant sign-in. An authenticator app is useful when those options are unavailable. Never approve a sign-in prompt you did not initiate or give someone your one-time code.
Protect recovery too
Secure your email account because it can reset other accounts. Store backup codes safely, keep recovery information current, and lock your devices. Change a password if it is compromised or exposed; follow your organization’s requirements. Use a password manager’s secure sharing features when authorized rather than sending passwords in messages.
Choose the safer account plan
Choose a plan for a fictional student’s email account. No real passwords are requested or collected.
Check your understanding
Choose one answer for each question, then check your answers. You can retry as often as you like.