Skip to main content
Password Security

Your Password Is a Liability: Ditch It for Passphrases and a Manager

Passwords are the weakest link in cybersecurity. Long passphrases and a password manager are your best defense. Here's how to fix it now.

Here's the stat that should make you sit up: Microsoft reports more than 300 million fraudulent sign-in attempts to its cloud services every single day (Microsoft Security Blog). That's not a typo. Three hundred million. And a huge chunk of those attempts succeed because people reuse passwords, use easy-to-guess ones, or never turn on multi-factor authentication. The truth is, your password is a liability. And the fix isn't a longer, more complex password. It's a passphrase and a password manager.

The Old Rules Are Dead

For years we were told to mix uppercase, lowercase, numbers, and symbols. Change it every 90 days. Don't write it down. That advice is outdated. NIST, the federal agency that sets digital identity guidelines, now explicitly forbids forced complexity rules and mandatory periodic password changes (NIST SP 800-63B). Why? Because complexity rules lead to predictable patterns—like "Password1!"—and forced changes make people tack on a number at the end. Instead, NIST says passwords should be at least 15 characters when used alone, and you should be allowed to use spaces and even emoji. The goal is length, not complexity.

Passphrases Beat Passwords

So what does a strong password look like? The UK's National Cyber Security Centre recommends building a passphrase from three random, unrelated words—like "apple nemesis biro" (NCSC). CISA, the US cybersecurity agency, suggests four to seven unrelated words, possibly with spaces (CISA Use Strong Passwords). Why does this work? Because length is the key factor in resisting brute-force attacks. A 16-character passphrase is far harder to crack than an 8-character password with symbols. And it's easier to remember. The old advice to swap 'o' for '0'? NCSC says that adds little strength. You're better off with a longer, memorable phrase.

The Password Manager Is Non-Negotiable

Here's the hard part: you have dozens of accounts. You can't remember a unique 16-character passphrase for each one. That's where a password manager comes in. CISA recommends using a password manager to generate and store unique, random passwords for every account, eliminating password reuse (CISA Secure Our World). This is not optional. If you reuse passwords, a breach on one site becomes a breach on all your accounts. Microsoft points out that password reuse enables credential-stuffing attacks, where attackers try your breached password against other services (Microsoft Security Blog). A password manager solves this by creating a different, strong password for every site and storing them securely. Yes, you still need one master passphrase—but that's the only one you have to remember.

MFA Is Your Second Layer

Now, even with a strong passphrase, a password alone isn't enough. Enable multi-factor authentication (MFA) on every account that supports it, starting with email, banking, and cloud accounts (CISA Secure Our World). Microsoft says enabling MFA can block over 99.9 percent of account compromise attacks (Microsoft Security Blog). That's a huge number. But beware: not all MFA is equal. SMS codes can be intercepted via SIM swapping, and push notifications can be exploited with "push bombing." CISA recommends phishing-resistant MFA, like hardware security keys or passkeys, as the gold standard (CISA Implementing Phishing-Resistant MFA). If you can't use that, an authenticator app is better than SMS.

The Counterargument: "I'm Not a Target"

You might think, "I'm just a regular person. Why would anyone target me?" But the data says otherwise. The FBI's IC3 received 859,532 complaints in 2024, with reported losses of $16.6 billion (FBI IC3 2024). And phishing is the most-reported crime category, with 193,407 complaints (FBI IC3 2024). Attackers don't target you personally; they cast a wide net. They use phishing emails, credential-stuffing, and automated bots. Even if you're not a high-value target, your email account can be used to reset passwords for your bank, your social media, your work. And once they're in, they can impersonate you. So yes, you are a target.

What I'd Actually Do

Here's my concrete recommendation, and it's simple. First, get a password manager today. I don't care which one—just pick a reputable one and use it. Second, change your passwords for critical accounts—email, banking, cloud—to a passphrase of at least 16 characters. For email, make it 20 characters. You can use a phrase like "purple elephant rocket ship"—just make sure it's random and not a quote from a book. Third, turn on MFA for every account that offers it. Use an authenticator app or a hardware key, not SMS. Fourth, check your email addresses on Have I Been Pwned to see if they've been in a breach (Have I Been Pwned). If they have, change those passwords immediately. And finally, stop reusing passwords. Ever. The 300 million attacks a day are real. Don't be the low-hanging fruit.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
  • NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • CISA (Use Strong Passwords) - https://www.cisa.gov/secure-our-world/use-strong-passwords
  • Have I Been Pwned - https://haveibeenpwned.com/About

Share this article:

Comments (0)

No comments yet. Be the first to comment!