How to create truly secure passwords
Updated: August 2026 · By César Cerrudo
Imagine using the same key for your house, your car, your office and your safe. If someone gets a copy, they have access to everything.
The exact same thing happens with passwords. The most dangerous problem usually isn't having an imperfect password. It's reusing it.
Every important account should have a different password
If a company suffers a breach and your password is exposed, attackers can automatically try it on Gmail, Microsoft, Facebook, Instagram, Amazon and financial services.
This attack works because millions of people reuse passwords.
Use long passwords
In general, a long, hard-to-guess password beats a short one full of predictable substitutions.
For example, turning password into P@ssw0rd doesn't magically turn a bad password into a good one.
A password manager changes the problem
It's hard to remember 80 different passwords. And you shouldn't try.
A password manager can generate and store unique credentials for every service. You mainly need to remember the master password.
Turn on MFA
A password can leak. That's why important accounts should have a second barrier: multi-factor authentication means knowing the password isn't necessarily enough to get in.
Consider passkeys where available
Passkeys aim to eliminate much of the traditional password problem and reduce certain phishing attacks.
You don't need to convert everything overnight. But when your main services offer them, they're worth evaluating.
1. Don't reuse. 2. Use a manager. 3. Protect important accounts with MFA.
The guide devotes a full chapter to passwords, second factors and passkeys, with the "protection ladder" to find out what level you're at today.
Want to learn how to protect all your accounts, your family and your business?
DOWNLOAD A HACKER'S SECURITY GUIDE FREE →