Password Hygiene Fundamentals
Why strong passwords matter, how to create them, and common mistakes.
Password Hygiene Fundamentals
Your password is your first line of defense against account compromise. Many breaches happen not because the company's system was hacked, but because someone used a weak password.
The Numbers
- 81% of data breaches involve weak or stolen passwords
- The average password is reused across 4.3 different sites
- 92% of people use the same password across multiple accounts
How Passwords Get Compromised
Dictionary Attacks: Attackers use lists of common passwords (123456, password, qwerty) and test them.
Credential Stuffing: Attackers buy dumps of breached usernames and passwords, then try them on other sites.
Shoulder Surfing: Someone watches you type your password.
Phishing: You enter your password on a fake login page.
Creating Strong Passwords
A strong password is:
- 12+ characters long (longer is better)
- Mix of character types: uppercase, lowercase, numbers, symbols
- Unique to each account
- Not based on personal info: no birthdays, names, or pet names
- Not predictable patterns: no qwerty sequences or incremental numbers
Good examples:
- Tr0pic@lSunset!2024
- BlueM00n#FireFly$
- Random pass phrases (CorrectHorseBatteryStaple)
Bad examples:
- password123
- MyDog2019
- 123456
- qwerty
The Reality: Use a Password Manager
Creating and remembering 50+ strong passwords is impossible. Use a password manager:
- Generates strong random passwords
- Remembers them for you
- Encrypts them with one master password
- Autofills securely
Options: 1Password, LastPass, Bitwarden, Apple Keychain
Knowledge check
What makes a password strong?
What's the biggest risk of reusing the same password across sites?