Supplementary — not from your PDF
Beginner
~30 min
Audit your passwords with a password manager
Use a reputable password manager's built-in health report to find weak or reused passwords on your own accounts and replace them.
Environment
A reputable password manager, such as the one built into your browser or a dedicated app.
Before you start
- Read Password Concepts (p.82) and Password Managers (p.83).
You will
- Find weak and reused passwords
- Generate long unique passwords
- Understand the master-passphrase risk
Steps
-
1
Open your password manager and run its password health, security check or 'watchtower' report.
-
2
List how many passwords are reused, weak, or flagged as exposed in known breaches.
-
3
For your three most important accounts (email first), generate a new random password of 16+ characters and change it on the site.
-
4
Turn on MFA for the password manager itself if it isn't already on.
-
5
Write two sentences on the trade-off: one strong vault versus many remembered passwords.
Check your understanding
- ?Why is your email account the most important to protect first?
- ?What does length add to a password's strength compared with complexity rules?
- ?What would happen if your master passphrase were phished, and which control limits the damage?