The most important password habit is uniqueness. One stolen password should not unlock several accounts.
Strong and unique passwords
Use a long, unique password for every important account. Length and unpredictability matter more than forced substitutions such as replacing one letter with a symbol. Do not reuse an email password on shopping, social, or entertainment sites.
Password managers
A reputable password manager can create and store unique passwords. Protect it with a strong master password and available account-recovery safeguards. Browser password storage may be adequate for some users when the device account is protected and synchronized carefully.
Never send passwords through ordinary email or chat.
Multifactor authentication
Multifactor authentication requires another proof beyond the password, such as an authenticator app, security key, or code. App-based prompts or security keys are generally preferable where available. Never approve a sign-in prompt you did not initiate or give a verification code to a caller.
Recovery and account review
Keep recovery email addresses and phone numbers current. Store backup codes securely. Review active sessions, connected apps, forwarding rules, and recent sign-ins after an alert or suspected compromise.
Start with the email account because it can often reset other accounts.
Quick skill check
- Use a unique password for each important account
- Protect the email account first
- Enable multifactor authentication
- Keep recovery details current
- Reject unexpected sign-in prompts