In close protection there is an old rule: a chain is only as strong as its weakest link. In digital security, that weakest link is almost always the password, specifically that one favourite password you use in five different places. Today I will show you how to deal with it properly, with minimal effort.
Why a reused password is a silent risk
When a password leaks from one service, attackers automatically try it on hundreds of others: email, banking, social media. This is called credential stuffing, and it works only because of one human habit: reusing passwords. Firms that track this report vast numbers of login credentials circulating among attackers every year. That is exactly why one weak, reused password can open up your whole digital life, even if you never shared it with anyone. All it took was a leak somewhere else, from a service you never gave a second thought to.
There is a free and entirely reputable way to check this yourself: haveibeenpwned.com. Enter your email address and it shows you which publicly known breaches it has appeared in. I recommend that everyone reading this article tries it. It is not unusual to find yourself there.
How a secure password manager works
The principle is simple, and the same as with a safe: one strong password, known as the master password, unlocks an encrypted vault in which every service has its own long, random password. You do not have to remember them; the manager does that for you. Good password managers also work on a zero-knowledge basis. Even if someone got into their servers, they would see only an unreadable heap of encrypted data, because the key to decrypt it is held only by you, in your master password. You are the only person who knows it.
Which one to choose
Bitwarden is my first recommendation for most people. It is free for basic use, its source code is open for anyone to inspect, and it regularly undergoes independent security audits, the results of which it publishes. 1Password is a paid but highly polished alternative with good sharing for families and businesses. Proton Pass comes from the same company as Proton VPN, which I recommended in the VPN article; if you want your privacy tools with one trusted provider, it makes sense. And for those who want to keep everything entirely on their own devices, with no cloud at all, there is KeePassXC: free and open source, but you have to sort out synchronisation between devices yourself.
A note on why I am specific in my recommendations. With a password manager, what matters to me is not just the marketing but also how a company handles its own security incidents. The clearest example is LastPass. In 2022 attackers first stole parts of its source code from the development environment, then used that information to obtain backups of customer vaults. LastPass itself confirmed that users’ passwords and secure notes in those vaults were encrypted, but other fields, such as the addresses of websites visited and basic account information, were not. It also admitted the full extent of the breach only several months later. I have no wish to disparage anyone; an incident can happen to any company. What I watch is how quickly and openly a company communicates, and what the real consequences of the breach were. In this case, investigators and security researchers have linked the stolen vaults to a series of later cryptocurrency thefts, which LastPass disputes. That is exactly why I recommend Bitwarden and 1Password above: they offer the same zero-knowledge foundation and, to date, a cleaner record of handling security.
One development of recent years is passkeys: a way of signing in with no password at all, where your device proves your identity with a cryptographic key. They are spreading quickly, but they are not everywhere yet, and not every service supports them. The good news is that the major password managers can already store passkeys alongside ordinary passwords, so there is no need to wait for the switch. When passkeys are everywhere, your password manager will handle them from day one.
A master password you will not forget
The strongest master password is not a tangle of letters and symbols that you cannot recall a week later. It is a string of four to six random, ordinary words, perhaps separated by hyphens. The human brain is good at remembering words and stories, not random characters. Let the words be generated for you (most password managers include a passphrase generator) rather than choosing them yourself; words picked by people tend to be predictable. Mathematically, a password like this is stronger than most “complex” passwords with capitals and symbols, and you will remember it first time.
Families and businesses: sharing without mistakes
The most common mistake I see with clients is not choosing the wrong password manager, but sharing passwords completely outside it: by SMS, WhatsApp, email or in an Excel spreadsheet on a shared drive. Most established password managers have a built-in secure sharing feature, where the password is encrypted for a specific person and never travels unencrypted. Use that feature rather than improvised workarounds, even if simply sending the password in a message feels quicker.
For clients who also consider what would become of their digital life if something happened to them, some password managers offer an emergency access feature. You nominate a trusted person in advance who, after a waiting period you choose, can access your vault if you do not respond yourself. It is an elegant answer to a question most people put off until it is too late.
What to do when a breach alert arrives
A good password manager will warn you itself if one of your stored passwords appears in a new public breach. When that happens, the procedure is simple: change the affected password immediately, check whether you have used the same password anywhere else, and if so, change it there too. And turn on two-factor authentication wherever you can. That is the subject of my next article, because a password alone, however strong, should never be the only barrier between an attacker and your account.
“A strong password that you use everywhere is like a single key to your flat, your office and your car. Convenient, until it falls into someone else’s hands.” — Robert Václavík




