After you email, shop online, and post on social media, do you ever ask yourself: “are my passwords secure?” Here’s why it matters, and how to create a password that’s both secure and easy to remember.
Passkeys: the replacement for passwords
Like the floppy drive, passwords are on their way out, and their replacement is already here. Passkeys are a shared standard from Apple, Google, and Microsoft that let you sign in with your face, fingerprint, or device PIN. There is nothing to remember, and nothing for an attacker to phish or steal. They are now supported across every major platform and a fast-growing list of sites. Wherever a service offers a passkey, use it.
Why we don’t rely on LastPass or 1Password
Keeping all of your passwords on a third-party system isn’t as secure as we’d like. If a single hacker gets into that one account, they suddenly have all of your passwords. It has happened:
- LastPass hacked: password manager with 25 million users confirms breach
- Which password managers have been hacked?
How to create a secure password
Must haves
- More than text: strong passwords are at least 8 characters and mix upper and lower case letters, numbers, and symbols (!*@&#^$%).
- Nothing obvious: no easily guessed information like your birth date, phone number, or a spouse’s, pet’s, or kid’s name.
- Avoid words: skip common words like “boat” or “cookie.” Base words like a pet’s name or a color make the weakest passwords.
Create a secure password
- Memorable: start with a phrase, motto, or affirmation about 12 words long. For example, “Abundance And Joy Fill Up My Heart And My Life With Energy.”
- Abbreviate it to its first letters:
aajfumhamlwe. - Then harden it with capitals, numbers, and symbols:
A&Jf9Mh+Mlw/E.
Mix it up
- Differentiate: add something specific to each service. For Apple you might append
aP, so your password becomesA&Jf9Mh+Mlw/EaP; for Amazon,aZ, soA&Jf9Mh+Mlw/EaZ.
Turn on two-factor authentication
A strong password is step one; two-factor authentication (2FA, sometimes called MFA) is step two, and it’s the single biggest security upgrade you can make. Even if someone gets your password, they can’t get in without the second factor.
- Prefer an authenticator app (Google Authenticator, Microsoft Authenticator, or Authy) or a hardware key over SMS text codes, which can be intercepted or SIM-swapped.
- Turn it on for your email first. Email is the master key that can reset every other account, so protect it above all.
- Save your backup codes somewhere safe in case you lose your phone.
How will I know if my password is secure?
These free tools test your password’s strength. They don’t know who you are or where you use it, so they’re safe to try.
Why have a different password for each service?
If you use the same password everywhere, Facebook, Instagram, Amazon, iTunes, Google, Netflix, one breach puts all of them at risk. Automated bots skim the web looking for a way into any account. When they crack one, they immediately try that same password everywhere else. Different passwords for each account dramatically lower your odds of getting hacked.
When should I share my password with support?
Never. Seriously. If an email from your bank, your insurer, or even iTunes or Amazon asks you to share your account info, it’s a scam. No legitimate company asks you to breach your own security. If you think something’s wrong, go to the service directly and log in; any real security message will be waiting in your account. Otherwise, call the company directly. Never use the link or phone number from the suspicious email.
Learn more
- Apple helps with your Apple ID password.
- Google helps you secure your passwords.
- Microsoft offers more on strong passwords.
Updates to this article
2026: Reviewed and refreshed. A strong password is still the foundation, but on its own it is no longer enough. Two-factor authentication is now essential, and passkeys have gone mainstream. Both are covered in the sections above.
2023: Apple, Google, and Microsoft aligned on passkeys as the replacement for passwords.
2017: Comparitech released a handy secure password generator.
2014: In response to Heartbleed, here is a good piece on changing your passwords regularly. We suggest doing it at each Daylight Saving switch.
Apple’s Safari also has a built-in suggestion system that saves strong passwords to your iCloud Keychain and syncs them across your Apple devices, accessible only by you. Allow Safari to suggest a password and you’re done.
