562 Passwords, Secure Sign-In, and Account Protection | Creating Passwords That Are Hard to Guess, and Changing Sign-In Details After a Security
Passwords and sign-in controls protect the entrance to many personal accounts. Strong protection depends on more than choosing a complicated word: people also need different credentials for important accounts, a safe way to store them, added verification where available, and awareness of unusual sign-in activity.
These chapters focus on practical account access. They explain how to make passwords harder to guess, avoid one stolen password opening several accounts, keep credentials safely, use two-step verification, recognize suspicious access, and change sign-in details after a security concern.
562.1 Creating Passwords That Are Hard to Guess
A password is harder to guess when it is long, uncommon, and not built from information that another person could easily discover. Names, birthdays, phone numbers, simple number sequences, and familiar words are common choices and therefore weak starting points. Length gives more room for variation, while a passphrase made from several unrelated words can be easier to remember than a short string of confusing substitutions.
The password should also be created for the account rather than copied from an obvious pattern used everywhere else. Adding one changed digit to the same base word across many accounts gives only limited separation. Where a service sets password rules, those rules should be followed, but meeting the minimum requirement does not automatically make the result strong. The aim is a credential that is difficult for another person or automated guessing system to predict, while still being manageable enough that the owner does not write it in an exposed place or share it casually.
562.2 Using Different Passwords for Important Accounts
Reusing one password across important accounts turns a single leak into a wider security problem. If a password is exposed through one website, an attacker may try the same email address and password on mail, social media, shopping, cloud storage, or other services. This can work even when the other services themselves were never breached.
Separate passwords are especially valuable for accounts that can reset other accounts or reveal sensitive information. Email, financial services, work systems, and the main account connected to a phone are common examples. Less important accounts should not become a shortcut into these higher-value ones. A password manager can help people maintain many different credentials without memorizing each one, but even without one, the principle remains useful: avoid repeating the same secret across places where one compromise could spread. Separation contains damage by making stolen credentials less useful elsewhere.
562.3 Keeping Passwords Safe Without Relying on Memory
Trying to remember every strong, unique password can lead people to simplify them, reuse them, or keep them in unsafe places. A password manager is one practical option: it stores credentials in an encrypted vault and can create long random passwords. The vault itself needs strong protection because it becomes an important point of access. People should choose a reputable manager, protect its main password carefully, and use additional verification when the service offers it.
Other storage methods may also be reasonable in some circumstances. A written record kept privately in a secure physical place can be safer than a short reused password, especially for someone who does not use a password manager. What matters is who can reach the record and whether it exposes all important accounts at once. Passwords should not be left in open notes, visible messages, or files shared with others. Safe storage reduces memory pressure without turning convenience into easy access for the wrong person.
562.4 Using Two-Step Verification
Two-step verification adds another check after a password, such as a code from an authenticator app, a security key, a device prompt, or a one-time code sent by a service. If a password is stolen, the extra step can prevent the attacker from signing in immediately. The available methods differ between services, and some are stronger against phishing than others, but any properly configured second step can add useful protection.
The extra code or approval should be treated as part of the sign-in secret. A person who did not start a login should not approve a prompt simply because it appears on the phone, and a code should not be read out to someone claiming to provide support. Recovery options also deserve attention: backup codes or an alternative recovery method should be stored where they can be reached if the main device is lost. Two-step verification works best when it strengthens access without creating a recovery problem later, especially for accounts that can reset other services.
562.5 Recognizing an Unusual Sign-In
An unusual sign-in can appear as an alert from a service, a new device listed in account settings, a login from an unfamiliar location, or activity that the account owner does not recognize. Location information is not always exact, and normal events such as travel, a new phone, or a changed network can create alerts. The important question is whether the sign-in matches something the owner actually did.
If it does not, the safest check is through the service itself rather than through a link in the alert. Open the official app or type the known website address, review recent sessions or security activity, and look for other changes such as a new recovery address, changed settings, or messages sent without permission. If unauthorized access seems likely, secure the account promptly. A real alert is useful because it gives an early warning; a fake alert is itself a common phishing method, which is why independent access to the account matters before any sign-in details are entered.
562.6 Changing Sign-In Details After a Security Concern
A security concern may justify changing sign-in details even before there is proof that an account was taken over. Examples include entering a password on a doubtful website, discovering that a reused password was exposed elsewhere, finding an unknown session, or learning that another person has seen the credential. The change should be made from a device and connection that are believed to be safe, using the official service rather than a suspicious message link.
Choose a new password that has not been used on the account before and, if the old password was reused, change the other important accounts that share it. Review recovery email addresses, phone numbers, trusted devices, and active sessions so that an intruder has not left another way back in. Two-step verification can then add a further barrier. Changing only the visible password without checking recovery and session settings may leave the underlying access problem unresolved and allow another person to return later.