Length beats complexity, uniqueness beats cleverness, and a manager beats memory. The current guidance, explained.
Length beats complexity
Forced symbol-and-number rules produced passwords that were hard for humans and easy for machines. Current guidance favours length: a long passphrase of unrelated words resists cracking far better than a short string of substituted characters.
Uniqueness matters more than strength
A brilliant password reused across twenty sites is weaker than twenty mediocre unique ones, because a single breach compromises all twenty accounts at once. Uniqueness is the single highest-value change most people can make.
Running a password manager properly
The manager holds everything, so protect it correctly and plan for the worst case.
- Choose one strong master passphrase you never use anywhere else
- Enable two-factor authentication on the vault itself
- Store recovery codes on paper somewhere physically secure
- Import and then securely delete any exported browser CSV file
- Run the built-in breach and reuse audit every few months
Where passkeys fit in
Passkeys replace the password with a cryptographic key stored on your device, which makes phishing structurally impossible for that account. Adopt them where offered, but keep the manager: plenty of services will still be password-only for years.