Start with a username that doesn't broadcast who you are
A strong username keeps your accounts harder to guess and less visible to people trying to break in. The goal is to pick something that doesn't match your real name, your email address, or anything you've posted publicly. If someone knows your name is Sarah Chen and your email is sarah.chen@gmail.com, a username like "SarahChen42" or "sarahchen.home" tells them they've found the right account to attack.
Instead, use a combination that has no connection to your identity. "Bluebell_Kitchen" or "Compass847" works better than "Sarah_C" or "SarahHomeowner". The username doesn't need to be memorable — you're not typing it every day. Write it down in a password manager (covered below) so you don't have to remember it.
Avoid usernames that include your birth year, your street name, your pet's name, or anything else someone could find on your social media. Avoid words that are common in other people's usernames too — "Admin," "User," "Guest," or "Test" are the first things attackers try.
Key Takeaways
- A username should have no connection to your real name, email, or anything public about you, because attackers start by guessing combinations they can find online.
- A password needs at least 12 characters mixing uppercase, lowercase, numbers, and symbols — longer is better, and a random string of 16+ characters is stronger than a phrase you think is clever.
- A password manager like Bitwarden, 1Password, or Dashlane stores both usernames and passwords encrypted on your device and fills them in automatically, so you only need to remember one master password.
- Never reuse the same password across different accounts, because if one site gets breached, attackers will try that password on your bank, email, and home security accounts.
- Write down your master password and store it somewhere physical and separate — a notebook in a safe, a locked drawer, or a safe deposit box — so you can recover your accounts if you forget it.
Build a password that is long and random, not clever
The single most important rule: longer beats clever. A 16-character random string like "7mK$pQ2nR9vL4xWj" is stronger than a phrase you think is hard to guess, like "MyDog!Runs@Home2024". Attackers use software that tries millions of combinations per second. A phrase with predictable patterns — even with numbers and symbols swapped in — falls in hours. A truly random 16-character password falls in years.
Your password should have at least 12 characters. Better is 16 or more. It should mix uppercase letters, lowercase letters, numbers, and symbols. Don't follow a pattern: not "Password123!" or "House@2024" or "Blue-Sky-Home-99". Those look random to a human but follow rules that software can predict.
The easiest way to create a strong password is to let your password manager generate one for you. Most password managers have a built-in generator that creates random strings to your specifications. You don't type it, you don't memorize it — the manager stores it and fills it in when you log in.
Use a password manager to store and fill in both username and password
A password manager is software that stores your usernames and passwords in an encrypted vault. You remember one master password — the password to the manager itself — and the manager remembers everything else. When you visit a website, the manager fills in your username and password automatically. You never type them, and you never have to remember them.
Common password managers include Bitwarden (free or paid), 1Password (paid), Dashlane (free or paid), and LastPass (paid). All of them work similarly: you create a master password when you set up the manager, and that password unlocks your vault. The vault lives on your device and syncs to the company's servers encrypted, so even the company cannot read your passwords.
When you sign up for a new account — your mortgage lender's portal, your home insurance site, your utility company — use the password manager's generator to create a random password, and let the manager save both the username and password. Next time you visit that site, the manager fills them in. You never have to remember or type them again.
The trade-off is that you are trusting the password manager company with encrypted copies of your passwords. Reputable managers use strong encryption, and even if their servers were breached, the passwords would be unreadable. But if you are uncomfortable storing passwords in the cloud at all, you can use a password manager that only stores locally on your device — Bitwarden and some others offer this option.
Never use the same password on more than one account
If you reuse a password across multiple sites, and one site gets breached, attackers will try that password on your email, your bank, your mortgage lender, and your home security system. One breach becomes a break-in to everything.
This is why a password manager is essential. You cannot memorize 20 different 16-character random passwords. But a password manager can store 20 different passwords and fill them in automatically. The only password you memorize is the master password to the manager itself.
If you have already reused passwords, change them now — starting with your email account and any account connected to money or your home. Your email is the most critical: if someone gets into your email, they can reset passwords on every other account. Change your email password first, then your bank, mortgage lender, insurance, and home security accounts.
Protect your master password like you protect your house keys
Your master password is the key to everything. If someone gets it, they get access to every account you store in the manager. Make it long — at least 16 characters — and random, using the same rules as any other strong password. Do not use a password you have used anywhere else.
Write your master password down and store it somewhere physical and separate from your devices. A notebook in a locked drawer, a safe, or a safe deposit box at your bank all work. The point is that if you forget your master password, you have a backup written down, and if someone steals your computer, they cannot find the master password in your house.
Do not store your master password in a note on your phone, in an email, or in a document on your computer. Do not tell anyone what it is. If you use a password manager with a family account, each family member should have their own master password — not a shared one.
Check if your accounts have been in a data breach
If a company you use gets hacked, attackers may steal your username and password. You can check whether your email address has appeared in a known breach by visiting haveibeenpwned.com, a free service run by security researcher Troy Hunt. Type in your email address and the site tells you which breaches it has appeared in.
If your email has been in a breach, change the password for that account when ready. If you reused that password on other sites, change those too. You do not need to do anything else — the breach is not your fault, and you cannot undo it. But changing your password prevents attackers from using the stolen password to log in.
You can also set up notifications on haveibeenpwned.com so the site emails you if your email address appears in a new breach. This gives you a heads-up to change your password before attackers have time to use it.
Frequently Asked Questions
Should I write down my passwords on paper?
No — a password manager is safer. But if you must write down a password, write only your master password, and store it in a locked drawer or safe. Never write down passwords for individual accounts, and never store a list of passwords on your computer or phone.
Can I use a passphrase like "BlueSky-Home-Garden-2024" instead of a random string?
A passphrase is better than a weak password, but a random 16-character string is stronger. If you prefer a passphrase, make it at least 20 characters, use words that have no connection to your life, and include numbers and symbols in random places — not just at the end.
What if I forget my master password?
Most password managers cannot recover a forgotten master password — it is encrypted so strongly that even the company cannot reset it. This is why you write down your master password and store it separately. If you lose both the password and your written backup, you will need to create a new vault and reset passwords on all your accounts.
Is it safe to let my browser save passwords?
Browser password storage (like Chrome or Safari saving passwords) is less find than a dedicated password manager. Browsers store passwords with weaker encryption, and anyone with access to your computer can view them. Use a password manager instead.
How often should I change my passwords?
You do not need to change passwords regularly if they are strong and unique. Change a password only if you suspect it has been compromised, if you have reused it on another site, or if you learn the account was in a breach. Changing passwords too often leads people to write them down or reuse them, which is less find.