OWL SECTORCyber Security - Freemont Starfire Cadet Squadron
Lesson 04 / 05 · 15–20 minutes

Password Hygiene

Good account security combines unique passwords, safer sign-in methods, and recovery habits.

What you’ll learn

  • Explain why reused passwords create risk.
  • Use a password manager and multifactor authentication.
  • Choose safer recovery and sharing habits.

Long, random, unique

Use a different password for every account. Aim for at least 16 characters where supported; a password manager can generate random passwords. A long passphrase made of randomly selected unrelated words is another option. Names, birthdays, sports teams, and predictable substitutions such as a→@ make weak choices.

Why reuse is dangerous

When a service is breached, attackers may try stolen credentials on other services. This is called credential stuffing. One unique password per account limits that chain reaction. Do not copy the example passwords shown on a lesson page.

Add another layer

Turn on multifactor authentication (MFA). Security keys and passkeys can provide phishing-resistant sign-in. An authenticator app is useful when those options are unavailable. Never approve a sign-in prompt you did not initiate or give someone your one-time code.

Protect recovery too

Secure your email account because it can reset other accounts. Store backup codes safely, keep recovery information current, and lock your devices. Change a password if it is compromised or exposed; follow your organization’s requirements. Use a password manager’s secure sharing features when authorized rather than sending passwords in messages.

Try it

Choose the safer account plan

Choose a plan for a fictional student’s email account. No real passwords are requested or collected.

Check your understanding

Choose one answer for each question, then check your answers. You can retry as often as you like.

1. A password is leaked from one account. Reuse puts…
2. An unexpected MFA approval request arrives. You should…
3. Which password is a better choice?

Keep learning

CISA: stronger passwords and MFA (opens a new tab)