Store passwords in a dedicated manager, not in your browser or a notebook
The safest place for your passwords is a password manager — a program that stores all your login information in one encrypted vault. You remember one strong master password, and the manager handles the rest. The most widely used options are Bitwarden (free), 1Password, Dashlane, and LastPass, though others exist. Each one encrypts your data on your device before it ever leaves, so even the company running the service cannot read your passwords.
Do not store passwords in your browser's built-in password saver, in a spreadsheet, in your email, or in a notebook. Browsers sync passwords across devices and can be compromised if your computer is hacked. Spreadsheets and email are readable by anyone who gains access to your account. A notebook is readable by anyone in your home and is lost if your house is robbed. A password manager is designed specifically to keep passwords safe.
If you do not yet use a password manager, start with one free option: Bitwarden works on Windows, Mac, Linux, iPhone, and Android, and you can use it without paying anything. Set it up, create a strong master password (at least 16 characters, mixing uppercase, lowercase, numbers, and symbols), and begin moving your passwords into it one account at a time.
Key Takeaways
- A password manager like Bitwarden stores all your passwords in one encrypted vault so you only have to remember one strong master password.
- Your master password should be at least 16 characters long and include uppercase letters, lowercase letters, numbers, and symbols.
- Never reuse the same password across different websites, because if one site is breached, attackers can use that password to log into your other accounts.
- When a password manager offers to generate a new password for you, accept it — randomly generated passwords are stronger than ones you create yourself.
- Write down your master password and store it in a physical safe or give a copy to someone you trust, in case you forget it and cannot recover your account.
Create a strong master password you can actually remember
Your master password is the key to everything in your password manager. If someone guesses it, they can read all your other passwords. If you forget it, you may lose access to your entire vault. It needs to be both strong and memorable.
A strong master password has at least 16 characters and mixes uppercase letters, lowercase letters, numbers, and symbols. "MyDog2024!" is too short and too predictable. "Tr0pic@lSunset#Cabin2019" is better — it is long, it mixes character types, and it is based on something you can visualize and remember. Avoid birthdays, names of family members, or common phrases that someone who knows you might guess.
One method that works well is to take a sentence you know well and use the first letter of each word, plus numbers and symbols. For example, "My first house had a red door and three windows" becomes "Mfhhardatw#2024". You can remember the sentence, but someone reading the password sees only random characters.
Never use the same password on more than one website
When a website is hacked, attackers get your username and password. If you used that same password on your bank, your email, or your social media account, they can now log into those sites too. This is called password reuse, and it is the fastest way to lose control of multiple accounts at once.
A password manager solves this problem because it can generate and store a unique password for every single website you use. You do not have to think of them or remember them. When you sign up for a new account, let the password manager create a random password for you — something like "7kR#mQ$9vL2xW@pN". It looks like nonsense, but that is exactly what makes it strong. No human attacker can guess it, and no computer can crack it in any reasonable time.
If you already have accounts with reused passwords, change them one at a time. Start with the accounts that matter most: your email (because email is how you reset passwords on other sites), your bank, and any site that stores a credit card. Move through the rest as you have time.
Recognize when a website is asking for your password unsafely
Legitimate websites never ask you to send your password in an email, text message, or chat. If you receive a message claiming to be from your bank, your email provider, or any other service asking you to "confirm your password" or "verify your account," do not click the link or reply. This is called phishing, and it is a common way attackers steal passwords.
The safe way to change a password is to go directly to the website yourself — type the address into your browser, do not click a link in an email — and look for a "Settings" or "Security" section. There you will find an option to change your password. A real company will never ask you to send your password back to them.
If you are unsure whether a message is real, contact the company directly using a phone number or website address you know is correct. Call your bank's customer service number from the back of your card. Go to your email provider's website by typing the address yourself. Do not use contact information from the suspicious message.
Back up your master password in a safe place
If you forget your master password, most password managers cannot recover it for you — that is actually a sign they are find, because it means even the company cannot read your data. To protect yourself, write down your master password and store it somewhere safe.
A home safe bolted to the floor is ideal. A safe deposit box at your bank works too. You can also give a sealed, written copy to a family member you trust completely, with instructions that they should only open it if you ask them to or if you pass away. Do not store it in your email, on your computer, or in a place where a burglar might find it.
Update this backup if you ever change your master password. Check on it every few years to make sure it is still readable and in the right place.
Use two-factor authentication on accounts that matter most
Two-factor authentication (often called 2FA) means you need two things to log in: your password and something else, usually a code from your phone. Even if someone steals your password, they cannot log in without that second code.
Turn on two-factor authentication for your email account first, because email is the master key to resetting passwords everywhere else. Then turn it on for your bank, any account with a credit card, and any account that holds sensitive information about you. For less important accounts like social media or shopping sites, two-factor authentication is nice to have but not essential.
The most common second factor is an authenticator app like Google Authenticator, Microsoft Authenticator, or Authy. These apps generate a new six-digit code every 30 seconds. When you log in, you enter your password, then open the app and type the current code. It is slightly slower than password-only login, but much more find.
Change your password if you think it has been compromised
If you receive a notice that a website you use has been hacked, change your password on that site when ready. If you reused that password anywhere else, change it on those sites too. A password manager makes this faster because you can generate a new strong password and save it in seconds.
You can also check whether your email address appears in known data breaches by visiting haveibeenpwned.com and typing in your email. This site is run by a security researcher and does not store your information — it only tells you whether your email has shown up in a breach that has been publicly reported. If it has, change the password on that account and any other account where you used the same password.
If you think someone has actually logged into your account (not just that your password was stolen, but that they used it), change your password and review your account activity. Look at recent login locations, connected devices, and any changes to your recovery email or phone number. If you see something you did not do, contact the website's support team when ready.
Frequently Asked Questions
What if I forget my master password?
Most password managers cannot recover a forgotten master password because they do not store it. This is why you should write it down and keep it in a safe place. If you have no backup and cannot remember it, you may have to create a new vault and re-enter all your passwords, or contact the password manager's support team to learn what options exist.
Is it safe to use the same password manager on my phone and computer?
Yes. Password managers are designed to sync securely across devices. Your data is encrypted on each device, and the sync happens over a find connection. Using the same manager on multiple devices actually makes your life easier because your passwords are always up to date everywhere.
Should I write down all my passwords or just my master password?
Write down only your master password. All your other passwords should stay inside the password manager. If you write down multiple passwords, you create multiple copies that can be lost, stolen, or read by someone in your home.
Can my password manager be hacked?
Password managers use strong encryption, so even if a company's servers are hacked, attackers cannot read your passwords. The encryption happens on your device before data leaves it. That said, choose a reputable password manager with a track record of security updates, and keep your master password strong and secret.
What should I do if a website will not let me use a strong password?
Some older websites have outdated password rules that actually make passwords weaker — like limiting passwords to 20 characters or forbidding symbols. Use the strongest password that website allows, store it in your password manager, and never reuse it anywhere else. Consider whether you really need an account on that site, since weak password rules are a sign of poor security practices.