How to Secure Your Passwords: A Simple Guide That Actually Works

Passwords are the keys to almost everything in your life now: your email, your bank, your photos, your health records, your online shopping and your social media. Yet most of us still manage them the way we did twenty years ago, with a handful of memorable words, a couple of numbers and a lot of reuse.

That is exactly what criminals count on. When a website is hacked and its customer details leak, those emails and passwords are tried on other sites automatically, thousands at a time. If you use the same password in several places, one breach can open all of them. This guide explains, in plain language, how to secure your passwords properly without needing a perfect memory or a technical background.

Why weak and reused passwords are such a problem

There are three common ways passwords are stolen, and none of them involve someone guessing your dog's name.

  • Data breaches. A company you have an account with is hacked and its customer list is published or sold. This happens regularly, to businesses of all sizes.
  • Phishing. A fake email, text or website tricks you into typing your password into the wrong place. Our post on the signs of a scam email or text explains how to spot these.
  • Guessing and cracking. Programs try millions of common passwords and variations very quickly. Short or predictable passwords fall almost instantly.

Once criminals have one working password, they try it elsewhere. This is called credential stuffing, and it is why reuse is the biggest risk of all. A weak password on a minor shopping site becomes a problem if the same one protects your email.

What makes a strong password

The old advice was to mix capitals, numbers and symbols, then change it every few months. That led to passwords that were hard to remember and easy to crack, such as a word with a number on the end. Current guidance, including from the Australian Cyber Security Centre, favours length and unpredictability over complexity.

  • Make it long. Aim for at least 14 characters. Each extra character makes cracking dramatically harder.
  • Make it unpredictable. Avoid names, birthdays, addresses, favourite teams and anything on your social media.
  • Make it unique. Every important account should have its own.

Try a passphrase

A passphrase is a string of four or more random, unrelated words, such as a sentence that means nothing. It is long, easy to type and far easier to remember than something like a jumble of symbols. The key word is random. A famous quote or a line from a song is not random enough. Pick words that have no connection to each other, and avoid obvious patterns.

The practical answer: use a password manager

Nobody can remember dozens of long, unique passwords. That is not a personal failing. It is simply not how human memory works. The solution is a password manager, which is a secure app that creates, stores and fills in your passwords for you.

With a password manager, you only need to remember one strong master password or passphrase. Everything else is created and remembered by the app. Good password managers also:

  • Generate long, random passwords for each site automatically.
  • Fill them in on your phone, tablet and computer, so you can sync between devices.
  • Warn you if a password is weak, reused or has appeared in a known breach.
  • Only fill in passwords on the genuine website, which helps protect you from fake ones.
  • Store other sensitive notes, such as Wi-Fi codes, in an encrypted form.

Options include the password manager built into your Apple or Google account, a browser's built-in manager, and dedicated paid and free apps. Any reputable one is far better than reusing passwords. The best choice is the one you will actually use, so ease of use matters more than brand.

Is it safe to keep all my passwords in one place?

It is a fair question. Reputable password managers encrypt your data so that even the company cannot read it, and they are far safer than reused passwords, sticky notes or a document on your desktop. The weak point is your master password and your device, so make the master password long and unique, and turn on two-factor authentication for the manager itself.

Turn on two-factor authentication

Two-factor authentication, often shortened to 2FA or MFA, adds a second step when you log in. After typing your password, you also confirm a code or approve a prompt. Even if a criminal has your password, they cannot get in without the second step.

Start with your most important accounts:

  1. Your main email. It can reset the passwords for almost everything else.
  2. Online banking and payment apps.
  3. myGov and other government accounts.
  4. Apple ID or Google account.
  5. Social media and shopping accounts that hold your card details.

Where there is a choice, an authenticator app or a security key is stronger than a text message code. A text code is still much better than nothing, so do not wait for the perfect option. And never read out a code to someone who contacts you. A genuine company will not ask for it.

A step-by-step plan for fixing your passwords

You do not have to change everything overnight. Here is a manageable way to work through it.

  1. Secure your email first. Change the password to a long, unique passphrase and turn on two-factor authentication.
  2. Choose a password manager and set up a strong master password. Write the master password down and keep the paper somewhere safe at home until you know it by heart.
  3. Change passwords for banking, government and key accounts. Let the manager generate each new one.
  4. Work through the rest gradually. Update a few accounts each week. Prioritise anything holding money, personal details or photos.
  5. Check for breaches. Free services such as Have I Been Pwned let you enter your email address and see whether it has appeared in a known breach. If it has, change the affected passwords.
  6. Remove old accounts. Close accounts you no longer use. Fewer accounts means fewer ways in.

Common password mistakes to avoid

  • Reusing passwords. The single biggest risk.
  • Adding a number to an old password. Changing "Sunshine1" to "Sunshine2" does not fool anyone.
  • Storing passwords in an unprotected file, an email draft or your phone's notes app.
  • Sharing passwords by text or email. If you need to share access, use the sharing features in a password manager.
  • Answering security questions truthfully. Your mother's maiden name and first school are easy to find. Treat the answers like extra passwords and make them up, then store them in your manager.
  • Ignoring updates. Software updates close security gaps that no password can protect against.
  • Typing passwords into links from messages. Always go to the website or app yourself.

Passwords for the whole household

Passwords are not just a personal matter. Your home WiFi, router, smart TV, cameras and streaming accounts all have them too, and many are still on the factory settings. Changing the router's admin password and WiFi password takes a few minutes and closes an easy door. If you have older parents, help them set up a password manager or a simple, secure written system kept at home, and check that their email is protected with two-factor authentication. For a broader plan, see our guide to scam protection at home.

For small businesses, shared logins are a risk. Each staff member should have their own account, and access should be removed promptly when someone leaves. Our small business IT support service can help set this up properly.

Get help setting it up

Changing dozens of passwords sounds tedious, and many people put it off for years. That is where a little help goes a long way. When we visit, we can set up a password manager on your phone and computer, help you secure your email and key accounts with two-factor authentication, move your saved passwords across, and show you how to use it all day to day. Our scam awareness and online safety service covers this as part of a one-on-one safety check, and our computer help for seniors service is patient and unhurried.

We come to homes across Balwyn, Kew, Camberwell, Doncaster, Box Hill, Blackburn and the surrounding eastern suburbs. Call 0400 771 828 or send a message to book. We work Monday to Saturday, 8am to 8pm.

Computer trouble? We'll come to you.

On-site computer repairs and IT support across Melbourne's eastern suburbs — homes, small business and seniors. Upfront pricing, plain English, no jargon.