Password reuse turns one breach into a risk for several accounts. A password manager solves the problem of remembering different strong passwords.
1. Use a different password for every account
Never reuse the same password for email, banking, shopping and social media. If one site is breached, unique passwords prevent attackers from simply trying the same login elsewhere.
2. Prefer long and random
A password manager can generate a long random password for each site. If you must remember one, use a long passphrase made from several unrelated words. Avoid names, birthdays, football teams and predictable substitutions.
3. Choose a password manager carefully
Use a well-known provider, protect the vault with a strong master passphrase and enable two-factor authentication on the password-manager account. Install it only from its official website or app store.
4. Save recovery details
Record recovery codes for your password manager in a secure offline location, not in an unprotected note on the same phone. Make sure a trusted recovery email is current.
5. Replace weak or reused passwords first
Most password managers can identify reused or weak passwords. Start with email, financial accounts, Apple/Google/Microsoft accounts and social media. Do a few at a time and confirm each login works.