Skip to main content
Privacy Tools

Stop Changing Passwords: Use a Password Manager and MFA Instead

Forget the advice to change passwords often. The real fix for password fatigue is a password manager plus MFA. Here's the blunt truth and how to do it.

You've been told to change your passwords every few months, use a different one for every site, and never write them down. That advice is nonsense. It's impossible for a human to remember dozens of unique, random 16-character passwords, so you end up reusing the same weak password everywhere, which is exactly what attackers count on. The blunt truth: the best password practice isn't memorization—it's delegation. Let a password manager handle the heavy lifting, and turn on multi-factor authentication (MFA) everywhere you can. That's the only realistic path to staying safe without losing your mind.

Why Changing Passwords Is a Waste of Time (and Even Dangerous)

The old advice to rotate passwords regularly was designed for a world where breaches were rare and passwords were the only defense. Now, breaches are routine, and attackers don't brute-force your password—they steal it from a company's database and try it on every other site you use. That's called credential stuffing, and it works because people reuse passwords. Changing a password every 90 days doesn't help if you're just swapping between two or three weak passwords you can remember.

What actually matters is that each of your accounts has a unique, random password that's long enough to resist guessing. According to CISA (Secure Our World), you should use a password manager to generate and store unique, random passwords for every account, eliminating password reuse. That's the foundation. If you're not using a password manager, you're relying on memory, and memory fails under the weight of hundreds of accounts.

The Real Rule: Long, Random, and Unique—Not Frequently Changed

So what makes a password strong? Length. CISA (Secure Our World) recommends passwords or passphrases of at least 12 to 16 characters, and up to 25 or more for the most sensitive accounts. But a long password you can remember is probably still predictable—think "correct horse battery staple" but with a twist. The better approach is to let a password manager generate a completely random 20-character string. You don't need to know it; the manager remembers it.

And if you think you can't trust a password manager, think again. The alternative is writing passwords on sticky notes, which is worse. A password manager is a single encrypted vault that requires one master password—make that one long and random, and enable MFA on it. That's the one password you actually need to know.

MFA Is Non-Negotiable—But Not All MFA Is Equal

Passwords alone are not enough. CISA (Secure Our World) says to enable MFA on every account that supports it, starting with email, banking, and cloud accounts. MFA adds a second layer of defense: even if an attacker has your password, they can't get in without the second factor.

But here's the catch: not all MFA is created equal. SMS codes are convenient, but they're vulnerable to SIM-swapping, where an attacker tricks your carrier into porting your number to their phone. CISA (Secure Our World) recommends preferring phishing-resistant MFA such as authenticator apps, hardware security keys (FIDO2), or passkeys over SMS codes. So, if you're using SMS, you're better than nothing, but you're leaving a hole. Upgrade to an authenticator app like Google Authenticator or Authy, or get a hardware key like a YubiKey for your most critical accounts.

Don't Forget the Basics: Check for Breaches and Update Software

Even with a password manager and MFA, you're not done. You need to know if your passwords have already been compromised. CISA (Secure Our World) suggests checking for breached credentials using tools such as Have I Been Pwned and rotating any compromised passwords. So, go to haveibeenpwned.com, enter your email, and see if you've been in a breach. If you have, change that password immediately, and make sure you're not reusing it anywhere else.

Also, keep your software updated. CISA (Secure Our World) emphasizes that you should update all software promptly, back up data securely (the 3-2-1 rule), and avoid public Wi-Fi for sensitive transactions. The 3-2-1 rule means three copies of your data, on two different media, with one offsite. That's a simple mental model.

Phishing Is the Real Threat—Here's How to Beat It

Even with strong passwords and MFA, you can still be tricked into giving up your credentials. Phishing is the number one way attackers get in. CISA (Secure Our World) says phishing often creates false urgency or fear; pause before acting, hover over links to see the real URL, and verify sender addresses for misspellings. And phishing isn't just email—it's smishing (SMS), vishing (voice), and quishing (malicious QR codes).

So, the next time you get an email that says "Your account has been locked, click here now," stop. Don't click. Hover over the link and look at the URL. If it's not the official domain, it's a phish. If the sender address has a typo like "amaz0n.com," it's a phish. And never give out your password or MFA code over the phone, because your bank will never ask for that.

Here's the concrete scenario: You use a password manager, so every account has a unique 20-character password. You have MFA enabled on your email, bank, and cloud storage, using an authenticator app. One day, you get a text that looks like it's from your bank, saying your account is frozen. You don't click the link. Instead, you open your browser, type your bank's URL manually, log in with your password manager, and see that everything is fine. You just avoided a phishing attack because you paused and verified.

That's the real world. The old advice to change passwords often is a myth. What works is a password manager, long random passwords, MFA, breach checking, and phishing awareness. Do that, and you'll be ahead of most people.

The One Thing to Remember

The single most important thing to remember is this: Stop trying to remember passwords. Let a password manager do it, turn on MFA on every account that supports it, and verify before you click. That's it. That's the whole secret.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • CISA (StopRansomware Guide) - https://www.cisa.gov/stopransomware

Share this article:

Comments (0)

No comments yet. Be the first to comment!