Weak or reused passwords are one of the most common ways hosting accounts, email and websites get compromised. A few simple habits make a big difference:
- Use a unique password for every account - if one site is breached, a reused password lets attackers into everything else too.
- Go long, not just complex - a random phrase of 4-5 unrelated words (e.g. purple-taxi-window-42) is both stronger and easier to remember than a short, complicated jumble.
- Avoid personal information - names, birthdays and pet names are easy to guess or find on social media.
- Use a password manager so you don't have to remember dozens of unique passwords yourself.
- Turn on two-factor authentication (2FA) wherever it's offered - even if your password leaks, 2FA stops most unauthorised logins.