Skip to main content
Privacy Tools

Why Passwords Alone Are a Privacy Disaster—and What Actually Works

Passwords are the weakest link in your privacy. Here's why you need a password manager and phishing-resistant MFA, and how to do it step by step.

If you're like most people, you've probably typed your password into a website and thought, "Is this really safe?" The answer, more often than not, is no. Passwords alone are a privacy disaster. I'm not being dramatic—the numbers back me up. In 2024, the FBI's Internet Crime Complaint Center (IC3) received 859,532 complaints with reported losses of about $16.6 billion, a 33% increase over 2023 (FBI IC3). And a huge chunk of that starts with a stolen password. So, what do you do? First, stop relying on passwords alone. Second, get a password manager. Third, turn on multi-factor authentication (MFA) that's actually resistant to phishing. Let's bust some myths and get you sorted.

Is it really that bad if I reuse a password for unimportant sites?

Yes, it is. You might think, "It's just my forum account, who cares?" But attackers don't care about your forum account—they care about the fact that you used the same password for your email or bank. Password reuse is what enables credential-stuffing attacks, where attackers try your stolen password on other sites (Microsoft Security Blog). And if you're thinking, "My password is long and has numbers and symbols," that's not the shield you think it is. The UK's National Cyber Security Centre (NCSC) points out that letter-to-symbol swaps, like changing 'o' to '0', add little strength (NCSC). The real defense is uniqueness: every account gets its own random password, and you let a password manager remember them.

Do I really need a password manager? They seem like a single point of failure.

I get the hesitation, but a password manager is the single best privacy tool you can adopt. It generates and stores unique, random passwords for every account, eliminating the nightmare of reuse (CISA Secure Our World). The "single point of failure" worry is overblown—you protect the manager with a strong master passphrase and MFA, and you've got a vault that's harder to crack than a reused password on a dozen sites. The NCSC explicitly recommends password managers, and even says writing down a password is acceptable if you keep it safe (NCSC). So, yes, you need one. No more excuses.

What's the deal with passphrases? Are three random words actually secure?

The NCSC's advice is to use three random, unrelated words—like 'applenemobiro'—because they're long enough and strong enough, yet easy to remember (NCSC). This is a solid step up from a single complex word. But here's the kicker: even a good passphrase is only as strong as its uniqueness. If you use 'applenemobiro' on two sites, you're back to square one. So, use a passphrase for your master password, but for everything else, let the password manager generate truly random strings. NIST, the federal guideline folks, recommend passwords of at least 15 characters when used alone, and they advise against forced complexity rules and mandatory periodic changes (NIST SP 800-63B). So, longer is better, but unique is non-negotiable.

I've heard that MFA can be hacked. Is it even worth it?

Yes, it's worth it, but not all MFA is created equal. CISA, the U.S. cybersecurity agency, documents four ways traditional MFA gets bypassed: phishing, push bombing (where you get bombarded with push notifications until you accept), SS7 protocol vulnerabilities, and SIM swapping (CISA Implementing Phishing-Resistant MFA). That sounds scary, but the fix is to use phishing-resistant MFA, like hardware security keys (FIDO2) or passkeys, which CISA ranks as the gold standard (CISA Implementing Phishing-Resistant MFA). If you can't use those yet, app-based one-time passwords or mobile push with number matching are better than SMS (CISA Implementing Phishing-Resistant MFA). And here's the kicker: Microsoft found that enabling MFA can block over 99.9% of account compromise attacks (Microsoft Security Blog). So, even basic MFA is a massive win.

Is it true that changing my password regularly is a good idea?

This is a myth that refuses to die. NIST explicitly forbids mandatory periodic password changes, because they encourage people to make small, predictable variations (NIST SP 800-63B). Instead, you should change a password only when you suspect it's compromised, and you can check that using a service like Have I Been Pwned, which lets you see if your email has appeared in a known data breach (Have I Been Pwned About). So, stop changing your passwords on a schedule. Change them when they're breached.

What about phishing? I never click on suspicious links.

We all think we're immune, but the stats say otherwise. Phishing and spoofing was the most-reported crime category to the FBI's IC3 in 2024, with 193,407 complaints (FBI IC3). And Verizon's 2024 Data Breach Investigations Report found that 68% of breaches involve a non-malicious human element, meaning someone fell for a phish (Verizon). Phishing can come as smishing (SMS), vishing (voice calls), or even quishing (malicious QR codes) (CISA Secure Our World). So, it's not about being smart—it's about being prepared. Hover over links to see the real URL, verify sender addresses for misspellings, and if something feels urgent, pause (CISA Secure Our World). And if you have phishing-resistant MFA, even a successful phish won't get the attacker in.

What if I've already been breached? Is it too late?

It's never too late. If you've been in a breach, the first step is to change that password immediately, and if you reused it anywhere else, change those too. Use Have I Been Pwned to check your email, and rotate any compromised passwords (CISA Secure Our World). Then, set up MFA everywhere. And here's a concrete scenario: imagine your email and password for an old forum got leaked. You used the same password for your online banking. An attacker uses that combo to log into your bank, and because you don't have MFA, they're in. That's how a breach on a random site becomes a financial disaster. So, yes, you can recover, but do it now.

What I'd actually do

Here's my concrete plan. First, sign up for Have I Been Pwned and check your email right now. Second, install a reputable password manager and generate a unique, random password for every account—start with your email, banking, and cloud accounts, as CISA advises (CISA Secure Our World). Third, enable MFA on those accounts, preferring a hardware key or passkey if possible; if not, use an authenticator app, not SMS. And finally, stop changing passwords on a schedule, and never reuse a password again. This won't make you invincible, but it will put you ahead of the vast majority of people. The numbers are clear: MFA blocks 99.9% of account attacks, and password managers eliminate the reuse problem. Do it today, not tomorrow.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
  • NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/

Share this article:

Comments (0)

No comments yet. Be the first to comment!