Passwords and Two-Factor Authentication: Lock Down Your Accounts
Most account takeovers don’t involve sophisticated hacking. Someone reuses a password, that password leaks in a breach, and criminals try it everywhere else. Fixing this takes an afternoon and stops the single most common way people get compromised.
Start with your email account
Your email is the master key: password resets for every other account land there. Secure it first.
- Give it a long, unique password used nowhere else.
- Turn on two-factor authentication (2FA) — in Gmail it’s under Security → 2-Step Verification; in Outlook, under Security → Advanced security options.
- Review the recovery phone and email on file. If an old number you no longer control is listed, remove it — attackers who take over that number can take over your inbox.
Use a password manager
You can’t remember 80 unique passwords, and you shouldn’t try. A password manager generates and stores a strong, random password for every site and fills them in for you.
- Pick one and commit — see our guide to the best password managers.
- Let it replace your reused passwords gradually: every time you log in somewhere, update that password to a generated one.
- Protect the manager itself with a long passphrase (four or five random words) and 2FA.
Set up two-factor authentication properly
2FA means a stolen password alone isn’t enough to log in. But not all second factors are equal:
- Best: a hardware security key (YubiKey or similar) or a passkey — both are immune to phishing, because they only work on the real site.
- Good: an authenticator app (Aegis, Google Authenticator, Microsoft Authenticator).
- Better than nothing: SMS codes. Vulnerable to SIM-swapping, so use app-based codes for email, banking and anything holding money or identity documents.
Save the backup codes each service gives you when you enable 2FA — store them in your password manager. They’re how you get back in if you lose your phone.
Do this today
- Turn on 2FA for your email account.
- Install a password manager and import your browser-saved passwords.
- Change any password you know you’ve reused, starting with email and banking.
- Check haveibeenpwned.com to see which of your accounts have appeared in known breaches — and change those passwords first.