Skip to main content

Why you do not need 27 different passwords

Passwords. The bane of modern existence. To celebrate this nuisance, the holiday gods have given us World Password Day, where thousands of people come together online and pledge to improve their password habits. How many of those pledges do you think stick? According to the 2017 Verizon Data Breach Investigation Report, not many. A little over 50 percent of all breaches in the last year leveraged either stolen or weak passwords.

Coincidentally, today is also Star Wars Day (May the 4th Be with You). And while we all wouldn’t mind having a lovable droid guard our passwords as loyally as R2D2 guarded the blueprints for the Death Star, the reality is we’ve got to do the guarding ourselves. And that has become burdensome enough to send Yoda himself over to the Dark Side.

Current state of affairs

According to a poll by Intel Security, the average person has 27 discrete online logins. From social media accounts to banking to online shopping to utilities, credentials—which usually include a username and password—are required for each. And if people are practicing good password hygiene, they’re engaging in the following recommended practices:
  • DO: Use a different password for each account.
  • DO: Use a long password. In fact, the longer, the better.
  • DO: Use special characters, numbers, and capital letters.
  • DO: Change your passwords every couple of months.
  • DO NOT: Write down your password, whether that’s on a piece of paper or stored electronically.
  • DO NOT: Share passwords via text, email, or chat.
  • DO NOT: Use easily identifiable information, such as a birthday or a child’s name.
  • DO NOT: Use an incredibly generic password such as 12345. (That’s the combination an idiot would use on his luggage.)
All of this, for 27 different logins, is simply unmanageable. In fact, the Intel study found that 37 percent of its respondents forgot a password at least once a week. And people are so sick of juggling dozens of different passwords, that 20 percent said they would give up ESPN if it meant never having to remember another one. Six percent said they’d give up pizza. PIZZA.

This level of discontent and security fatigue means that very likely, most users are falling back on bad habits: writing passwords down in a notebook or a Google sheet, for example, or using the same password across multiple logins. (A study by the National Institute of Standards and Technology confirms this: 91 percent of its respondents admitted to reusing passwords.)

So this is why we say: stop it. Stop the bad habits, yes, but stop the “good” ones, too. Having 27 different passwords that are lengthy and full of characters and numbers and need to be changed every few months and can’t be written down—you’d need the memory of an eidetic elephant to keep up. Online services will only multiply, so what should you do?
It’s very simple. Get a password manager.

Password manager 101

For those who might not be familiar, password managers assist in generating, storing, and retrieving passwords from an encrypted database. They typically require that users create and remember one master password to rule them all. One master password to find them. One master password to bring them all, and in the darkness bind them.

One master password to stand at the precipice and shout gallantly, “YOU SHALL NOT PASS!”
Sorry, it couldn’t be helped. As we were saying. Generally, most password managers work the same way. You’ll be asked to create a strong master password during setup (and here’s where you’ll use those password best practices, such as generating a long passphrase with numbers and capitals that steers away from guessable personal info). From there, you’ll add your other credentials to the password manager either manually or through tools that can automatically find and upload passwords for you.

While most password managers have similar setups, they secure passwords in different ways. Web-based password managers store your passwords encrypted in the cloud. Some are built into browsers, such as Safari, Firefox, and Chrome. Others may store your passwords locally in an encrypted file on your computer, tablet, or phone.

In addition, some password managers have features that help you audit your credentials, allowing you to weed out duplicate login info and remove sites you don’t use, or alerting you to breaches that have happened to the companies you log into. Many have customizations that allow increased security, such as regional lockout and two-factor authentication (which we highly recommend taking advantage of).

But aren’t I just asking to be hacked by storing everything in one place?

While some folks might be wary of using a single point of access for all their sites, remember that password managers still use your individual passwords to log in to your accounts. Those passwords are locked in an encrypted database, which is way more secure than a post-it on your office desk or a faulty memory. Ask yourself this: is it safer to store all your money in one bank or to hide it in piles underneath several mattresses?

As for fear of password managers being breached—sure, it’s possible. In fact, it’s already happened, as was the case in 2015 when LastPass was breached. However, even though cybercriminals got their hands on some email addresses, they were unable to crack master passwords. This is because master passwords are protected with military-grade security, hidden behind thousands of rounds of hashing, or algorithms that convert strings of text into longer strings of text. So far, no reputable password manager has leaked consumer master passwords (that we know of).

So which password manager should I use?

The following password managers come highly recommended by our staff and tech reviewers from The New York Times, Lifehacker, and PCMag:
If you don’t trust third-party apps with all of your personal information, you can try an open-source password manager such as KeePassX, though it requires a fair bit of technical know-how to set up.

I am absolutely opposed to a password manager. What else can I do?

While we stand by our recommendation to use password managers, we understand the urge to reject placing all your trust in the hands of another company. So here are a few alternate methods for choosing more secure passwords than the random hodgepodge you’re likely working with now.
  1. Split up your online services into major groups, such as bills, entertainment, shopping, and social media. Assign a single password to each group according to a theme. For example, you could choose movies as your theme and assign quotes from one movie to one group, or character names from a second movie to the second group. Rotate these passwords every 90 days by incrementally adding a number or changing a character. This requires a lot more effort but is still preferable to using the same password across all accounts or having to reset forgotten passwords every week.
  2. Choose one semi-difficult password for all accounts but insert a naming convention in the middle of the password to denote which account you are signing into. For example, if your password is L3tme1npleaz, your Gmail password could be L3tme1nGMAILpleaz. Your Amazon password could be L3tme1nAMAZONpleaz, and so on and so forth.
  3. When possible, choose a service that has two-factor authentication over one that does not. More than 150 applications currently implement two-factor authentication. 
Passwords don’t have to rule your life. You can lock them up behind a password manager and worry about remembering a single, slightly complex phrase instead of 27. You can relax knowing how well guarded your passwords are. And you can go ahead and burn that secret list of passwords you keep in your address book even though you’re not supposed to.

Do you have a favorite password manager? Or a method for creating and remembering unique passwords? Let us know in the comments below.

Posted: May 4, 2017
Malwarebytes Labs by Wendy Zamora
Last updated: May 3, 2017

Comments

Popular posts from this blog

Trump Administration Declares CFPB Funding Illegal, Bureau’s Cash To Run Out By Early 2026

WASHINGTON—Credit-unions face a potential regulatory vacuum as the Trump Administration formally has determined the CFPB’s current self-funding mechanism unlawful—a move that could put the agency on a path to closure in early 2026 unless Congress steps in. For credit-union leaders, who rely on the Bureau’s oversight of consumer-finance markets and enforcement of unfair practices, the decision signals a major disruption to the regulatory environment CUs navigate daily. In a court filing released late Monday, the Administration declared that the CFPB is now legally barred from seeking additional funds from the Federal Reserve System—the agency’s usual funding source under the Dodd‑Frank Wall Street Reform and Consumer Protection Act, POLITICO reported. That means the Bureau’s remaining resources will likely carry it only through the end of the year, after which it “anticipates exhausting its currently available funds in early 2026.” CUToday.info has tracked this story, noting in  Oct...

Now Available - "Financial Literacy" From NCOFCU

https://www.ncofcu.org/financial-literacy The National Council of Firefighter Credit Unions (NCOFCU) is dedicated to enhancing financial literacy among our members, members, particularly targeting the Millennial and Gen Z demographics. We are excited to share our engaging financial education video series, designed to address their key concerns regarding earning, saving, and spending money wisely. Here are several critical financial lessons that can significantly impact your personal finance management and long-term financial health. Discover how staying informed and educated about financial products and market trends can empower you to make smarter financial decisions. https://www.youtube.com/playlist?list=PLT3lzRTXnHw4LjHuOIk31eTDxaQ7J7B0f   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Sheehans Consulting LLC - "We only have one goal in mind!"

We have one goal in mind: “What is best for you? We achieve strategic initiatives, develop products, optimize profitability and productivity through best practices, and make our firm a strong asset for professional services.  With over 30 years of experience in public administration, credit union, and association management, I have developed a solid track record in leadership and development.  Please visit us at https://www.sheehansconsultingllc.com/ to learn more about what we can do for you.   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA Reports Continued Credit Union Loan Growth in First Quarter of 2016

"ALEXANDRIA, Va. (June 3, 2016) – Credit unions continued to increase their lending, with loans outstanding increasing 10.7 percent in the year ending in the first quarter of 2016, the National Credit Union Administration reported today.  “The credit union system again experienced solid performance during the first quarter of 2016,” NCUA Board Chairman Rick Metsger said. “Overall, new and used auto lending was especially strong, and the system gained one million members. With an influx of deposits, federally insured shares at credit unions also neared the $1 trillion mark coming in at $991.7 billion.  “As credit union lending has increased, long-term investments have declined and reduced the system’s interest rate risk. However, delinquency and charge-off rates are slightly higher than a year ago, and member-business loan delinquencies are rising even more. Credit unions making such loans should take note and ensure that they perform proper due diligence to mitigate the r...

Best Places to Retire

  List: Best Places to Retire Midland, Michigan , was ranked the best place to retire , according to a ranking of 850 cities by U.S. News . The top locations had the best mix of affordability, quality of life, health care access, and other benefits. The top five were rounded out by Weirton, West Virginia , Homosassa Springs, Florida , The Woodlands, Texas , and Spring, Texas . Midland scored top marks on walkability , culture , retail establishments , and restaurants . The town is just a short drive from beaches at the edge of Lake Huron . The top 25 included nine cities in Florida and six in Texas. See the full list here . _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

House Vote Ends Longest Shutdown In U.S. History

WASHINGTON—The House late Wednesday approved a sweeping funding measure to end the longest federal government shutdown in U.S. history, clearing the way for federal agencies to reopen within hours and for hundreds of thousands of workers and service members to receive long-delayed pay. The vote was 222-209, with just six Democrats breaking with their leadership, POLITOCO said. President Trump is expected to sign the measure before night’s end, allowing federal operations to resume Thursday morning. The chamber’s vote—coming after days of intense negotiations and following the Senate’s 60–40 passage—sent the bipartisan agreement to President Donald Trump for his signature, effectively ending a shutdown that stretched well past six weeks and rattled everything from military readiness to basic government services. The package includes a continuing resolution funding the government through Jan. 30. The measure also includes a three-bill “minibus” of full-year funding for the Department...

Fed Governor Warns ‘Global Stablecoin Glut’ Could Reshape Monetary Policy

  NEW YORK—Federal Reserve Governor Stephen Miran believes the rapid rise of stablecoins could become a major force shaping U.S. monetary policy. Once seen as a niche digital tool for crypto traders, stablecoins have evolved into a global conduit for dollar-denominated transactions, enabling users worldwide to store value and move capital more efficiently. Their growing prominence, Miran noted during his speech at the BCVC Summit 2025 at the Harvard Club, reflects continued demand for dollars—and with the GENIUS Act now providing a clear regulatory framework for U.S.-issued stablecoins, the sector is poised for broader adoption across payment systems. Stephen Miran Stablecoins’ link to the U.S. dollar is reinforcing the currency’s global dominance while simultaneously creating new implications for monetary policy. Miran argued that stablecoins are already increasing demand for U.S. Treasury bills and other dollar-based assets, especially from investors outside the United States. Th...

NCUA Letter to Credit Unions: Interagency Statement on LIBOR Transition

Dear Boards of Directors and Chief Executive Officers: As a follow-up to Letter to Credit Unions 21-CU-03, LIBOR Transition , this letter provides additional reminders related to LIBOR’s discontinuance. Five federal financial institution regulatory agencies, in conjunction with the state bank and state credit union regulators, are jointly issuing the enclosed statement to emphasize the expectation that supervised institutions with LIBOR exposure will continue to progress toward an orderly transition away from LIBOR. [1] The NCUA encourages all federally insured credit unions to transition away from using U.S. dollar LIBOR as a reference rate as soon as possible, but no later than December 31, 2021, and to ensure existing contracts have robust fallback language that includes a clearly defined alternative reference rate. Please contact your NCUA Regional Office or state supervisory authority if you have any questions about this important topic. Read the Letter to Credit Unions   Sav...

Are You Ready for the Next Wave of Mergers & Acquisitions?

Remember you are not alone with NCOFCU!  If you are consedering a merger reach out to us to see if we can't keep you within the first responder credit union network. ceo@ncofcu.org - 305.951.3306 ALM First shares key lessons and advice from credit unions with merger and community bank acquisition experience. By David Ritter & By Brandon Pelletier | April 10, 2024 at 09:00 AM Credit/Shutterstock With the pace of industry mergers already ramping up in 2024 and projected to increase, it's more important than ever for credit unions to have a predefined M&A strategy and be ready for the inevitable calls from prospective partner organizations. Here, we'll share key lessons and advice from cooperatives that have merger experience with other credit unions and acquisition experience with community banks to help your team prepare. Define Your Vision and Evaluation Criteria ...

NCUA Board Member Rodney E. Hood Remarks at the National Council of Firefighters Credit Unions (NCOFCU)

NCUA Director addresses NCOFCU attendees in Fort Worth TX.     Thank you very much for the kind introduction. It’s a pleasure to join you today, and I’m especially delighted that conditions are so much improved that we’re able to gather in person. After what we’ve been through the last year and a half, I think we’re all ready for a gradual return to a more normal footing, even if we still have some way to go to reach that point. I spend a lot of time studying what credit unions are doing, and one of the best parts of this job is that I’m regularly reminded of how powerful the credit union model can be for making a difference in our communities. This initiative is a true testament to the strength of that model. I certainly look forward to checking in on the progress of this program so we can see how it works – it looks like a promising experiment.  Read his complete p...