99.9%. That's the share of account compromise attacks Microsoft says multi-factor authentication blocks. If a tool doesn't move that number, it's not worth your time. So when someone asks me which privacy tools to install, I don't ask what's popular. I ask: which tools make the attacker's job so hard they move on to someone else? In my experience, only two categories do that reliably: password managers and phishing-resistant multi-factor authentication. Everything else is a distant third.
Why the password manager comes before the VPN
Privacy tool lists love VPNs. They're easy to sell and easy to understand. But a VPN doesn't stop credential stuffing, and credential stuffing is what actually gets accounts popped. Microsoft ties password reuse to password-spray and credential-stuffing attacks, where common or previously breached passwords get tried against corporate accounts. A password manager is the only consumer-grade tool that breaks that cycle by generating and storing a unique, random password for every single account.
I've watched people argue for an hour about which VPN has the best no-logs policy while their personal email password is the same as their bank password from 2016. That's backwards. Fix the credential layer first. The manager is the tool that makes the rest of your privacy stack matter, because an account you can't log into is an account whose data isn't exposed.
The length debate is settled — stop overthinking it
Every few months someone asks me whether they should use a 16-character random string or a passphrase. The guidance has converged, and it's more permissive than most people think. CISA recommends passwords of at least 16 characters and says longer is stronger, with a password manager generating and storing them. NIST goes further, requiring passwords used as a sole authentication factor to be at least 15 characters, and telling systems to accept up to at least 64 characters, including spaces and Unicode. The UK NCSC's answer is the one I give non-technical family members: three random, unrelated words, because that's 'long enough and strong enough' while still being memorable.
My recommendation: let the manager generate a 20-plus character random string for anything you never type, and use a four-to-seven-word passphrase for the one or two passwords you actually have to memorize — your manager master password and your device login. CISA explicitly endorses four-to-seven unrelated words, spaces allowed, as a memorable way to hit that length.
Quick tip: If your password manager master password is a single dictionary word with a number tacked on the end, you've built a vault with a screen door. Make that one a passphrase.
MFA is not a checkbox — the method is the whole point
Here's where I part ways with most privacy advice. 'Turn on MFA' is not useful guidance on its own, because CISA documents four distinct ways traditional MFA gets bypassed: phishing, push bombing, SS7 protocol exploitation, and SIM swapping. If your second factor is an SMS code, you've closed the front door and left the window open. SIM swapping is a social-engineering attack where someone convinces your carrier to move your number to a SIM they control — and then your 'secure' code goes to them.
So I rank MFA methods explicitly. At the top: FIDO2 security keys and passkeys built on WebAuthn, which CISA calls 'the only widely available phishing-resistant authentication'. If you can't do that yet, app-based one-time codes or push notifications with number matching are the acceptable middle. SMS and voice codes are last resort, full stop. The hardware key is the single best privacy purchase most people can make — it's the one tool that survives a phishing page, because it cryptographically binds to the real site and simply won't authenticate to a lookalike.
Where breach-checking fits — and where it doesn't
Have I Been Pwned is the free tool I recommend to literally everyone, and it's the rare privacy service with a clean story: Troy Hunt has run it since 2013, letting anyone check whether an email address appeared in a known breach. It was born after the Adobe breach, when the same accounts kept surfacing with the same passwords. That origin explains its real value — it's not a monitoring service, it's a prompt to rotate the specific passwords that leaked.
I treat it as a quarterly habit, not a subscription. Check your addresses, and if something shows up, change that password and anything that shared it. CISA recommends exactly this: check for breached credentials and rotate any compromised ones. What I don't do is pay for 'dark web monitoring' that just wraps the same breach data in a dashboard and a monthly fee.
Your phone is now the target
Privacy tools built for the desktop era are aging badly. Verizon's 2026 Data Breach Investigations Report found that mobile devices have become a favorite attack target, noting people are more likely to fall for a fake text or scam call than a traditional phishing email. That matches what I see: smishing and vishing — SMS and voice phishing — are where the successful compromises now start, and CISA lists both alongside quishing, the malicious-QR-code variant.
This changes what 'privacy tool' means. A password manager on your phone is only half the job if you're still reading SMS codes to a caller who claims to be your bank. The practical defense is procedural, not app-based: never read a code aloud, never tap a link in a text, and hang up and call back on a number you look up yourself. CISA's guidance is to avoid clicking or calling anything in a suspicious message and instead find another way to reach the organization directly.
Last month, my neighbor got a text saying her package was held at the post office. She clicked the link, entered her credit card for a $2 redelivery fee, and within ten minutes someone was buying gift cards with her card. She didn't have MFA on her email, so the attacker used the email to reset her bank password. Two tools would have stopped it: a password manager that auto-filled nothing on the fake site, and a hardware key on her email. That's it.
What I tell people to install first
If you gave me thirty minutes and one budget, here's the order. First, a reputable password manager — generate unique 20-plus character passwords, replace your reused ones, and store the recovery codes. Second, a hardware security key or passkeys on your email, banking, and cloud accounts, because those are the accounts that reset everything else. Third, turn on automatic updates everywhere, since an unpatched browser undermines every other tool you've installed. Fourth, run your email addresses through Have I Been Pwned quarterly.
Notice what's not on that list: a VPN, a paid identity-monitoring subscription, or an antivirus with a flashy dashboard. Those aren't worthless, but they don't address the number we opened with. The 99.9 percent lives in the authentication layer. Spend there first.
The single most important thing to remember: a password manager plus phishing-resistant MFA is the privacy stack. Everything else is optional. Get those two right and you've eliminated the overwhelming majority of real-world account takeovers; get them wrong and no amount of extra tooling will save you.
Sources
- Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- CISA (Use Strong Passwords) - https://www.cisa.gov/secure-our-world/use-strong-passwords
- CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- NIST SP 800-63B (Digital Identity Guidelines) - https://pages.nist.gov/800-63-4/sp800-63b.html
- NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
- Have I Been Pwned (About) - https://haveibeenpwned.com/About
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!