We're not leaving until yours works
In the previous class we installed the password manager. Everyone had it on a phone or computer before leaving, and a few of you had already added several passwords. Good — that's the part that genuinely matters.
Today we complete it. Not "read about completing it." Complete it, in this room, with me walking the rows.
Understand what installation does and does not accomplish. Installing the manager doesn't protect you; having your actual accounts inside it protects you. A password manager holding three passwords, while forty still live in your head — or, worse, on a folded piece of paper in your wallet — is not yet doing its job. That is today's entire agenda. We're going to sit here and move your real accounts in, one at a time, until yours is working.
Step one: choose your five
Don't attempt all your accounts today. Choose five, in this order:
- Your email. This is the critical one, because anyone who gets into your email can reset nearly everything else. Email first, always.
- Your bank or credit union.
- Whatever you use for bills — power, water, anything on autopay.
- Anything with a stored credit card. Amazon, if you use it. Costco's site, if you order online.
- Social media, if you use it much.
That's five. Five is a genuine afternoon's work, and five done well beats twenty done carelessly.
Step two: log in the old way, one final time
Go to the site or app. Log in with your current password as usual. While you're in there, locate "account settings" or "security," then find "change password." That's your target.
Step three: let the manager write the new one
This is the step people resist, so I'll state it plainly: don't type your own password. Let the manager generate one. Click the small dice or refresh icon — whatever your app calls it — and it will produce something like xR7!qmZ2vLp9. Ugly. Unmemorable. Ideal. Copy it into the site's "new password" field, save, done.
You will never type that password again. That isn't a defect; it's the entire point. You're not meant to know it. The manager knows it.
Step four: verify it actually saved
Log out of the account. Then log back in, letting the manager fill it in. If it works, you're finished with that one. If it doesn't, we fix it now, in this room, before you go home and forget which browser extension you're supposed to use. This is the "we're not leaving until yours works" portion, and I mean it literally. I would rather stack chairs twenty minutes late than have you leave here half configured.
A word about that "change password" screen
Some sites require you to clear several hurdles — old password, security questions, a code texted to your phone. That's normal; it's the site verifying that you're really you, and it's a good sign rather than an irritating one. If a site lets you change your password too easily, with no verification whatsoever, that one is genuinely worth double-checking that it's really you they emailed.
Why we do email first, always
I want to return to this, because it's the position I'll defend to the end in this class: your habits matter more than any software you buy. Antivirus subscriptions and the like are mostly noise now. What protects you is what you actually do — slowing down, checking, and, yes, securing your email first, because it is the master key to everything else.
Kylie, my neighbor, learned this the hard way, and I raise it in class deliberately, because it's precisely the kind of thing that happens to normal, careful people rather than careless ones. She received a call some time ago from someone claiming to be from Microsoft, saying her computer had a virus. She allowed them to remote into her machine to "fix it." By the time she reconsidered, they'd been examining it for a few minutes. We spent an afternoon wiping that computer and starting over.
Here is the part relevant to today. Her email password was old, it was weak, and it was the same one she'd used since she opened the account. Had that call gone differently — had they captured that password instead of merely poking around — they could have reset her bank login, her Amazon, everything, using her email as the entry point. The computer wipe was the straightforward fix. The password reuse was the real exposure, and it's the one we're closing today.
So: email first. Then bank. Then bills. Then the rest.
If you get stuck
Raise your hand. I'll come to you. Some of you are on iPhones, and I'll admit I have to look a few of these steps up alongside you — I'm an Android user at heart — but we'll get there together. If a site's "change password" screen behaves oddly, that's common, not a sign you did something wrong.
Before next time
Complete at least three of your five today if we run short in class, and finish the remaining two at home this week using the same steps. Don't wait for "a free afternoon" — you had one today.
~kenneth