99.9% of Account Attacks Stop With One Simple Change
That's the statistic Microsoft puts on enabling multi-factor authentication (Microsoft Security Blog (MFA)). But here's the uncomfortable truth: MFA is only as strong as the password it's bolted onto. If your password is 'Fluffy2020!' – a pet name and a year, something the NCSC explicitly warns against because it's often visible on social media – an attacker who phishes or steals that password can still cause chaos if they also intercept your SMS code or push notification. The real fix starts before MFA: with how you generate and store passwords. And that's where most of us are failing.
The Case for Your Brain: Three Random Words and the Human Touch
The UK's NCSC has championed the 'three random words' approach: pick three unrelated words, like 'applenemobiro', and you get a passphrase that's 'long enough and strong enough' yet memorable (NCSC (Three Random Words)). I'll admit, this has appeal. It's human. It doesn't require trusting a piece of software. You can write it down, and the NCSC says that's acceptable if you keep it somewhere safe. For a low-stakes account, maybe that's fine.
But here's the problem: your brain is a terrible database. It forgets. It takes shortcuts. It reuses passwords because remembering 50 unique passphrases is impossible. And the moment you reuse a password, you've handed attackers the key to multiple doors. Microsoft notes that password reuse enables credential-stuffing attacks, where criminals take a password leaked from one site and try it on your bank account (Microsoft Security Blog (MFA)). The NCSC's advice is sound for a single account, but it doesn't scale to the dozens of accounts we all have.
The Case for a Password Manager: Random, Unique, and Everywhere
CISA's advice is blunt: use a password manager to generate and store unique, random passwords for every account (CISA (Secure Our World)). That's the only way to eliminate password reuse entirely. A password manager like Bitwarden or 1Password can create a 20-character string of gibberish that you'd never remember, and it will autofill it when you need it. It also helps you avoid the trap of 'complex' passwords that are actually weak – think 'P@ssw0rd123', which the NCSC rightly dismisses because letter-to-symbol swaps add little strength.
And before you say 'but what if the password manager gets hacked?' – sure, it's a target, but it's a far better target than your brain. The password manager encrypts your vault, and you protect it with a strong master password plus MFA. That's a much smaller attack surface than your memory, which leaks passwords through phishing, social engineering, and your own habit of using the same password everywhere.
Head-to-Head: Brain vs. Password Manager
| Criterion | Your Brain (Three Random Words) | Password Manager |
|---|---|---|
| Password strength | Good for one password, but humans tend to pick predictable words | Generates truly random, long passwords (e.g., 16+ characters) that meet NIST's 15-character minimum for sole authentication (NIST SP 800-63B) |
| Unique passwords for every account | Impossible for most people | Easy – generates a new random password for each site |
| Resistance to phishing | Low – you might type your passphrase into a fake login page | Higher – the manager autofills only on the correct domain, so you're less likely to fall for a lookalike URL |
| Convenience | No software needed, but you must type it manually | Autofill, but you need to install and trust the software |
But Wait – What About MFA? The Real Winner Isn't Either
Here's my point of view: the debate isn't really 'brain vs. password manager.' It's 'single-factor vs. multi-factor.' Even the best password manager won't save you if an attacker steals your password and you have no MFA. That's why the real winner is a password manager plus phishing-resistant MFA. CISA ranks FIDO2 hardware keys and passkeys as the gold standard, because they resist phishing, push bombing, SIM swapping, and SS7 attacks (CISA (Implementing Phishing-Resistant MFA)). But until you get those, an authenticator app with number matching is better than SMS, which CISA says should be a last resort.
So here's my recommendation: use a password manager for all your passwords, and enable MFA on every account that supports it, starting with email, banking, and cloud. If you can't use a hardware key, use an authenticator app. And for the love of all that is secure, don't rely on your memory for anything except your master password – which should be a long passphrase you've never used anywhere else.
The One Thing to Remember
Your brain is a leaky sieve. The single most important thing you can do for password security is to stop trying to remember passwords and start using a password manager. Then turn on MFA. That's the combination that will stop 99.9% of account attacks – and it's not even close.
Sources
- CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
- NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
- NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
- Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!