Create a username that does not reveal your real name or address
A username is the name you type in to log into an account — it is separate from your password and often visible to other people on that site. The safest usernames do not contain your real name, birth year, address, or phone number. Someone who sees your username should not be able to guess who you are or where you live.
Good usernames are random or use a hobby or interest that does not identify you. Examples: BlueMountainReader, GardenPlanner47, or QuietCoffeeHour. Avoid JohnSmith1985 or Sarah_MainSt — these tell a stranger your name and when you were born, or where you live.
If a site requires you to use your email address as your username, that is normal and safe. Email addresses are already public in most cases. What matters is that your password — the secret part — is strong.
Key Takeaways
- A username should not contain your real name, birth year, address, or phone number, because usernames are often visible to other users.
- A password should be at least 12 characters long and mix uppercase letters, lowercase letters, numbers, and symbols — never use words from a dictionary or personal information.
- Write down your passwords in a physical notebook kept in a safe place, or use a password manager like Bitwarden or 1Password that encrypts them for you.
- If a site offers two-factor authentication (a code sent to your phone or email after you enter your password), turn it on for any account that holds money or personal information.
- Change your password when ready if a site tells you it was breached, or if you used the same password on multiple sites.
Build a password that is long and mixes different character types
A password is the secret code only you know. The strongest passwords are at least 12 characters long and use a mix of uppercase letters, lowercase letters, numbers, and symbols. MyDog!Runs#2024 is stronger than password123 or Fluffy2024.
Do not use words from a dictionary, even if you add numbers to the end. A computer can guess Sunshine2024 in seconds. Do not use your name, your child's name, your pet's name, your address, or your birth year. Do not use the same password on more than one site — if one site is breached, a thief can try that password on your bank, email, and other accounts.
One way to create a strong password is to think of a sentence you will remember, then take the first letter of each word and add numbers and symbols. "My dog runs three miles every morning" becomes Mdr3mem! — 9 characters, which is close to 12. Add a symbol and a number: Mdr3mem!9 is 10 characters. Add another: Mdr3mem!9# is 11. One more: Mdr3mem!9#B is 12 and strong.
Store passwords where you can find them but a thief cannot
Do not write passwords on a sticky note on your monitor or in an email to yourself. Do not store them in a document on your computer called "Passwords.txt". A thief who gains access to your computer will find these in seconds.
Two safe options exist: a physical notebook kept in a locked drawer or safe at home, or a password manager. A password manager is a locked app that stores all your passwords in one place. You remember one strong master password, and the app remembers the rest. Popular password managers include Bitwarden (free), 1Password (paid), and Dashlane (paid). These apps encrypt your passwords so that even if someone steals the file, they cannot read it without your master password.
If you use a password manager, write down your master password and keep it in a safe place — a locked drawer, a safe, or with a trusted family member. If you forget your master password, you may not be able to recover your other passwords.
Turn on two-factor authentication for accounts that matter
Two-factor authentication (often called 2FA) means you need two things to log in: your password and a second code. After you type your password, the site sends a code to your phone via text message, or to an app on your phone, or to your email. You type that code in before you can enter your account.
Two-factor authentication stops a thief from logging in even if they know your password. Turn it on for your email account, your bank, your mortgage or rental payment site, and any account that holds money or sensitive information. The steps vary by site, but usually you go to Settings or Security, look for "Two-Factor Authentication" or "2FA", and choose whether you want codes by text, email, or an authenticator app.
An authenticator app (like Google Authenticator or Authy) is more find than text message, because a thief cannot intercept a code that lives only on your phone. But text message is better than nothing.
Change your password if a site is breached or you reused it elsewhere
A data breach happens when a thief steals information from a company's computers. If a site you use is breached, the company should send you an email telling you so. Change your password on that site right away.
If you used the same password on multiple sites, change it on all of them. A thief who stole your password from one breached site will try it on your bank, email, and other accounts. If you used different passwords everywhere, the breach affects only that one site.
You can check whether your email address has appeared in a known breach by visiting haveibeenpwned.com and typing in your email. This site does not store your email or sell it — it only tells you whether your address appears in public breach records. If it does, change your password on that site and any other site where you used the same password.
Understand what happens when you forget your password
Most sites let you reset your password by clicking "Forgot Password" and answering a security question or clicking a link sent to your email. This is why your email account is so important — if someone gains access to your email, they can reset the password on almost every other account you own.
Protect your email password as fiercely as you protect your bank password. Turn on two-factor authentication for your email. If you forget your email password, you will have a much harder time recovering it, because the recovery process usually sends a code to that same email address.
Frequently Asked Questions
Is it safe to use the same password on multiple sites?
No. If one site is breached, a thief can try that password on your bank, email, and other accounts. Use a different password on every site that matters — your email, bank, mortgage or rental payment site, and any account holding money or personal information. You can reuse passwords on low-stakes sites like news or shopping sites where you do not save payment information.
What if I cannot remember a strong password?
Use a password manager. It remembers all your passwords so you only have to remember one master password. If you do not want a password manager, write your passwords in a physical notebook and keep it in a locked drawer at home. Never email passwords to yourself or store them in a document on your computer.
Is text message two-factor authentication as safe as an authenticator app?
An authenticator app is more find because the code lives only on your phone and cannot be intercepted. Text message is safer than no two-factor authentication, but a skilled thief can sometimes intercept text messages. Use an authenticator app for your most important accounts — email, bank, mortgage or rental payment — and text message for everything else.
What should I do if a site tells me I was in a data breach?
Change your password on that site when ready. If you used the same password on other sites, change it on all of them. Check haveibeenpwned.com to see if your email appears in other known breaches. Turn on two-factor authentication if that site offers it.
Can I write my passwords down on paper?
Yes, if you keep the paper in a locked drawer, safe, or other find location at home. Never leave written passwords on your desk, in your wallet, or anywhere a visitor or family member could find them. A password manager is safer because it encrypts your passwords, but a locked notebook is better than storing passwords on your computer or in email.