Why a password you can remember is already too weak
We have spent this course on calls, texts, and emails engineered to trick you into a bad decision in the moment. New module. This one is about the lock on the door rather than the person knocking on it.
Here is the position, stated up front, because I would rather you hear it early and argue with me through the rest of the lesson than feel I slipped it in at the end: if you can remember your password, it is already too weak. I know that is an irritating thing to hear. I have heard every objection there is. My brother Kelly has supplied most of them personally.
Why memorable means weak
A password you can hold in your head is assembled from things that are easy for you to think of. Children's names. Birthdays. The street you grew up on. A word plus the year plus an exclamation point because some website told you to add a symbol. That feels random to you. It is not random. It is a pattern, and patterns get guessed, either by a person who knows you slightly, or by software that does not know you at all and simply tries millions of combinations a second.
The other problem is worse. Because memorable passwords are hard to devise, people reuse them. The same password for email, for banking, for the grocery store loyalty app. Kelly does this. I pulled up a site that tracks breached passwords, and his appeared, sitting right there, exposed from some account he had probably forgotten he ever made. He changed one password afterward. One. Out of roughly thirty accounts. At least it was something.
That is the real danger of reuse. It does not matter how careful you are with your bank password if some low-security forum you joined in 2014 gets hacked and you used the same password there. That password is now loose in the world, tied to your email address, and anyone can begin trying it against your bank, your email, wherever.
The fix: stop remembering, start storing
A password manager is software that generates long, random, unique passwords for every account and remembers them so you do not have to. You need to remember only one thing: the master password that unlocks the manager itself. That one you make strong and memorable, because it is the only one your brain has to hold.
Steps to do this at home:
- Choose a password manager. Free ones are already built into your phone and browser, and there are dedicated apps as well. I will not name one, because that changes year to year and I want this lesson to hold true in five years. Search "password manager" and pick one with solid reviews. On an iPhone, some of this already lives in your Settings app under Passwords; I work on Android and Windows, so if you are on Apple I may need to look at your screen alongside you to walk through it.
- Set your master password. Make it a full sentence, not a single word. A phrase only you would think of, with spaces or without, it does not matter. Length beats cleverness. "correct horse battery staple" is a joke example that has circulated online for years, but it is a good one, because a random string of ordinary words is genuinely hard to crack and easy enough to remember, since it is only one thing.
- Let the manager generate new passwords for your accounts, one at a time. Start with email, because email is how a scammer resets everything else once inside it. Then banking. Then whatever else you use daily.
- Turn on the backup codes for your password manager itself before doing anything else. I mean before. Every manager provides some way to recover your account if you lose your device. Write those codes down and store them somewhere physical, not only digital.
I press that last step hard because I once locked myself out of my own email for an hour. I had set up two-factor authentication on a Saturday, felt very responsible about it, then switched phones a few weeks later and lost access to the codes. An hour of my own Saturday gone, staring at a login screen, because I performed the setup in the wrong order. Now I teach backup codes first, before anything else, specifically because of that hour. Learn from mine.
A caution, stated plainly
Do not write your master password on a sticky note on the monitor. I know that sounds obvious, but it is exactly what people did with individual passwords before, and old habits migrate to new systems if you let them. Write the backup codes down somewhere safe, certainly, but the master password itself should live in your head and nowhere else.
We are setting these up in class, row by row, before anyone leaves. Bring your phone and the email address you use most.
Before next time: decide which account you would be most upset to lose, email or banking, and have it ready to set up first when we sit down together.
~kenneth