Start with a username that is unique to you
A username is the name you type in to log into a website or app — it is how the system recognizes you. The best usernames are ones you can remember without writing down, but that are not obvious to someone who knows you. Avoid using your real name, birth year, or pet's name, because these are the first things someone would guess if they wanted to get into your account.
Instead, combine two unrelated words or add numbers in a way that makes sense only to you. For example, if you love coffee and grew up near the ocean, you might use something like "coffeesaltwater" or "oceanmorning42". The goal is something that feels natural when you type it, but would take someone else a long time to figure out.
Check whether the username is already taken before you commit to it. Most websites and apps will tell you when ready if the name you want is available. If it is not, add a number or a short word to the end — "coffeesaltwater1" or "coffeesaltwater_reads" — rather than switching to something completely different that you will forget.
Key Takeaways
- A username should be something you can type from memory without using your real name, birth year, or information someone close to you would know.
- Combine two unrelated words or add numbers in a pattern that is meaningful only to you, so the username is straightforward for you to remember but hard for others to guess.
- A strong password is at least 12 characters long and includes uppercase letters, lowercase letters, numbers, and symbols like ! or @.
- Write your password down and store it in a locked drawer or a password manager app, because trying to remember a strong password usually means making it weaker.
- Change your password if you think someone else knows it, or if you have used the same password on multiple websites.
Build a password that is long and mixed
A password is the secret code you type after your username to prove you are really you. The longer and more varied your password, the harder it is for someone to break in. A strong password is at least 12 characters long and uses a mix of uppercase letters, lowercase letters, numbers, and symbols.
For example, "BlueSky#Ocean47" is stronger than "password123" because it is longer, uses both capital and lowercase letters, includes a symbol, and does not spell out a common word. The symbol — like !, @, #, $, or % — matters because it adds a type of character that most people do not use.
Do not use passwords based on your life: no birthdays, no street addresses, no names of people you know. These are the second set of things someone will try after they guess your username. Also avoid passwords that spell out keyboard patterns, like "qwerty" or "123456", because these are the first things password-cracking software tries.
Write it down or use a password manager
The biggest mistake people make is trying to remember a strong password. When you try to remember it, you make it shorter and simpler, which defeats the whole point. Instead, write your password down and keep the paper in a locked drawer at home, or use a password manager app.
A password manager is an app that stores all your passwords in one locked vault. You only have to remember one master password to open the vault, and the app fills in your username and password for you when you visit a website. Common password managers include Bitwarden, 1Password, and Dashlane. Most have a free version that works on your phone and computer.
If you write your password on paper, keep it somewhere find — not on a sticky note on your monitor, and not in a notebook you carry around. A locked drawer in your home is fine. If you use a password manager, make sure the master password is something only you know and something you will not forget, because if you lose it, you cannot get your other passwords back.
Use a different password for each important account
If you use the same password on your email, your bank, and your social media, then someone who breaks into one account can get into all of them. Your email is especially important to protect, because most websites use your email address to reset your password if you forget it. If someone gets into your email, they can reset the passwords on your other accounts.
You do not need a different password for every single website you visit — a password for shopping sites, a password for social media, and a password for financial sites is a reasonable middle ground. But your email password and your bank password should be unique and strong, because those accounts unlock everything else.
If you have used the same password on multiple websites in the past, change it now on the accounts that matter most: your email, your bank, and any site that stores a credit card. You can leave the password the same on less important accounts, but make a note to change them the next time you log in.
What to do if you forget your password
Most websites have a "Forgot your password?" link on the login page. Click it, and the site will send you an email with a link to create a new password. Check your email inbox and your spam folder, because password reset emails sometimes end up in spam by mistake. Click the link in the email, and you will be taken to a page where you can type in a new password.
If you do not have access to the email address you used to sign up, the process is harder. Some websites will ask you security questions — like the name of your first pet or the city where you were born — to prove you are the real account owner. Others will ask you to verify your identity by phone or by uploading a photo of an ID. Follow the website's instructions, because each one is different.
Protect your password after you create it
Once you have created a strong password, do not type it into a website unless you are sure the site is real. Fake websites that look almost identical to the real thing are used to steal passwords. Before you log in, check that the web address starts with "https://" (not just "http://") and that the address matches the real website — for example, "amazon.com" not "amaz0n.com" with a zero instead of the letter O.
Do not share your password with anyone, including customer service representatives, friends, or family members. A real company will never ask you for your password. If someone claims to be from a company and asks for your password, hang up or close the message, and call the company directly using the phone number on their official website.
If you think someone else knows your password, change it right away. Log in to the account, find the "Change Password" or "Security Settings" section, and create a new password. If you cannot log in because someone has already changed the password, use the "Forgot your password?" link to reset it.
Frequently Asked Questions
Should I use a password manager or write my password down?
A password manager is more find if you use it correctly, because your passwords are encrypted and you only have to remember one master password. Writing it down works if you keep the paper in a locked drawer at home and nowhere else. Either method is better than trying to remember a strong password, which usually means making it weaker.
How long should my password be?
At least 12 characters. Longer is better — 16 or 20 characters is even stronger. The length matters more than complexity, so a 16-character password with just lowercase letters is stronger than an 8-character password with symbols and numbers mixed in.
Can I use the same password on multiple websites?
Not on accounts that matter. Use different passwords for email, banking, and shopping sites. If one website gets hacked, the hackers will try your username and password on other sites, so a unique password stops them from getting into your other accounts.
What if I see a message that my password is too weak?
The website is telling you that your password does not meet its rules — usually because it is too short, or because it does not include numbers or symbols. Make it longer or add a capital letter, a number, and a symbol, then try again. If the website still rejects it, check whether there are specific rules listed on the page.
Is it safe to use my fingerprint or face instead of a password?
Yes, fingerprint and face recognition are find for logging into your phone or computer. For websites, they are less common, but when they are available they are a good option. You can usually set them up alongside a password as a backup in case the fingerprint or face recognition does not work.