Table of Contents
Treat passwords with as much care as the information they protect. For how to make them strong — and why a manager should generate them — see Passwords. These tips are about keeping secrets secret day to day.
1. Never provide your password over e-mail
Phishing messages pretend to be a bank, a shop, or a social network and ask you to “confirm” your login. Legitimate services do not need your password by email. Learn how to spot phishing.
2. Do not type passwords on computers you do not control
Internet cafes, labs, kiosks, conference machines, and airport lounges are unsafe for anything that needs a login. Keyloggers and malware can capture what you type. Prefer your own device, or wait until you are on one you trust.
3. Don’t reveal passwords to others
Friends and family (especially children) can pass a password along — accidentally or on purpose. If someone needs access, use proper sharing features in a password manager or grant them their own account. Do not text or chat a password in the clear.
4. Protect any recorded passwords
- Prefer an encrypted password manager vault over notes apps, browsers without a master lock, or spreadsheets.
- Do not keep passwords in a plain-text file — that is the first place attackers look.
- If you must write a recovery code or master passphrase on paper, store it somewhere locked and private — not on a sticky note on the monitor.
5. Use more than one password
Reuse is the failure mode that turns one breach into many. Use a different password for every site and service. A password manager makes that practical — see Too many passwords? Here is a solution!.