ForgeAwareness
0 of 3 complete0%
Module 14 min

Password Hygiene Fundamentals

TL;DR

Why strong passwords matter, how to create them, and common mistakes.

Password Hygiene Fundamentals

Your password is your first line of defense against account compromise. Many breaches happen not because the company's system was hacked, but because someone used a weak password.

The Numbers

  • 81% of data breaches involve weak or stolen passwords
  • The average password is reused across 4.3 different sites
  • 92% of people use the same password across multiple accounts

How Passwords Get Compromised

Dictionary Attacks: Attackers use lists of common passwords (123456, password, qwerty) and test them.

Credential Stuffing: Attackers buy dumps of breached usernames and passwords, then try them on other sites.

Shoulder Surfing: Someone watches you type your password.

Phishing: You enter your password on a fake login page.

Creating Strong Passwords

A strong password is:

  • 12+ characters long (longer is better)
  • Mix of character types: uppercase, lowercase, numbers, symbols
  • Unique to each account
  • Not based on personal info: no birthdays, names, or pet names
  • Not predictable patterns: no qwerty sequences or incremental numbers

Good examples:

  • Tr0pic@lSunset!2024
  • BlueM00n#FireFly$
  • Random pass phrases (CorrectHorseBatteryStaple)

Bad examples:

  • password123
  • MyDog2019
  • 123456
  • qwerty

The Reality: Use a Password Manager

Creating and remembering 50+ strong passwords is impossible. Use a password manager:

  • Generates strong random passwords
  • Remembers them for you
  • Encrypts them with one master password
  • Autofills securely

Options: 1Password, LastPass, Bitwarden, Apple Keychain

Knowledge check

Knowledge check 1

What makes a password strong?

Knowledge check 2

What's the biggest risk of reusing the same password across sites?