The single highest-impact security habit: use a password manager. It generates and stores a unique, strong password for every site, so you only remember one master password.
Why reuse is the real danger
When one site is breached, attackers take the leaked email+password and try it everywhere else — credential stuffing. Reuse one password and a single breach unlocks your whole life. Unique passwords contain the damage to one account.
What a manager gives you
| Feature | Benefit |
|---|---|
| Generates random passwords | No more "Summer2024!" |
| Autofill | Convenient and anti-phishing (won't fill the wrong domain) |
| Breach alerts | Tells you what to rotate |
| Secure notes / sync | Encrypted across devices |
Choosing one
- Bitwarden — open-source, free, can self-host (Vaultwarden).
- 1Password — polished, paid.
- KeePassXC — fully offline, local file.
Your master password should be a long passphrase you never reused, protected with 2FA. It's the one key to everything — make it strong and unique. The vault itself is encrypted with strong crypto.
Related: 2FA and Passkeys · Password Hashing · Threat Modeling for Individuals