Skip to main content

Why you do not need 27 different passwords

Passwords. The bane of modern existence. To celebrate this nuisance, the holiday gods have given us World Password Day, where thousands of people come together online and pledge to improve their password habits. How many of those pledges do you think stick? According to the 2017 Verizon Data Breach Investigation Report, not many. A little over 50 percent of all breaches in the last year leveraged either stolen or weak passwords.

Coincidentally, today is also Star Wars Day (May the 4th Be with You). And while we all wouldn’t mind having a lovable droid guard our passwords as loyally as R2D2 guarded the blueprints for the Death Star, the reality is we’ve got to do the guarding ourselves. And that has become burdensome enough to send Yoda himself over to the Dark Side.

Current state of affairs

According to a poll by Intel Security, the average person has 27 discrete online logins. From social media accounts to banking to online shopping to utilities, credentials—which usually include a username and password—are required for each. And if people are practicing good password hygiene, they’re engaging in the following recommended practices:
  • DO: Use a different password for each account.
  • DO: Use a long password. In fact, the longer, the better.
  • DO: Use special characters, numbers, and capital letters.
  • DO: Change your passwords every couple of months.
  • DO NOT: Write down your password, whether that’s on a piece of paper or stored electronically.
  • DO NOT: Share passwords via text, email, or chat.
  • DO NOT: Use easily identifiable information, such as a birthday or a child’s name.
  • DO NOT: Use an incredibly generic password such as 12345. (That’s the combination an idiot would use on his luggage.)
All of this, for 27 different logins, is simply unmanageable. In fact, the Intel study found that 37 percent of its respondents forgot a password at least once a week. And people are so sick of juggling dozens of different passwords, that 20 percent said they would give up ESPN if it meant never having to remember another one. Six percent said they’d give up pizza. PIZZA.

This level of discontent and security fatigue means that very likely, most users are falling back on bad habits: writing passwords down in a notebook or a Google sheet, for example, or using the same password across multiple logins. (A study by the National Institute of Standards and Technology confirms this: 91 percent of its respondents admitted to reusing passwords.)

So this is why we say: stop it. Stop the bad habits, yes, but stop the “good” ones, too. Having 27 different passwords that are lengthy and full of characters and numbers and need to be changed every few months and can’t be written down—you’d need the memory of an eidetic elephant to keep up. Online services will only multiply, so what should you do?
It’s very simple. Get a password manager.

Password manager 101

For those who might not be familiar, password managers assist in generating, storing, and retrieving passwords from an encrypted database. They typically require that users create and remember one master password to rule them all. One master password to find them. One master password to bring them all, and in the darkness bind them.

One master password to stand at the precipice and shout gallantly, “YOU SHALL NOT PASS!”
Sorry, it couldn’t be helped. As we were saying. Generally, most password managers work the same way. You’ll be asked to create a strong master password during setup (and here’s where you’ll use those password best practices, such as generating a long passphrase with numbers and capitals that steers away from guessable personal info). From there, you’ll add your other credentials to the password manager either manually or through tools that can automatically find and upload passwords for you.

While most password managers have similar setups, they secure passwords in different ways. Web-based password managers store your passwords encrypted in the cloud. Some are built into browsers, such as Safari, Firefox, and Chrome. Others may store your passwords locally in an encrypted file on your computer, tablet, or phone.

In addition, some password managers have features that help you audit your credentials, allowing you to weed out duplicate login info and remove sites you don’t use, or alerting you to breaches that have happened to the companies you log into. Many have customizations that allow increased security, such as regional lockout and two-factor authentication (which we highly recommend taking advantage of).

But aren’t I just asking to be hacked by storing everything in one place?

While some folks might be wary of using a single point of access for all their sites, remember that password managers still use your individual passwords to log in to your accounts. Those passwords are locked in an encrypted database, which is way more secure than a post-it on your office desk or a faulty memory. Ask yourself this: is it safer to store all your money in one bank or to hide it in piles underneath several mattresses?

As for fear of password managers being breached—sure, it’s possible. In fact, it’s already happened, as was the case in 2015 when LastPass was breached. However, even though cybercriminals got their hands on some email addresses, they were unable to crack master passwords. This is because master passwords are protected with military-grade security, hidden behind thousands of rounds of hashing, or algorithms that convert strings of text into longer strings of text. So far, no reputable password manager has leaked consumer master passwords (that we know of).

So which password manager should I use?

The following password managers come highly recommended by our staff and tech reviewers from The New York Times, Lifehacker, and PCMag:
If you don’t trust third-party apps with all of your personal information, you can try an open-source password manager such as KeePassX, though it requires a fair bit of technical know-how to set up.

I am absolutely opposed to a password manager. What else can I do?

While we stand by our recommendation to use password managers, we understand the urge to reject placing all your trust in the hands of another company. So here are a few alternate methods for choosing more secure passwords than the random hodgepodge you’re likely working with now.
  1. Split up your online services into major groups, such as bills, entertainment, shopping, and social media. Assign a single password to each group according to a theme. For example, you could choose movies as your theme and assign quotes from one movie to one group, or character names from a second movie to the second group. Rotate these passwords every 90 days by incrementally adding a number or changing a character. This requires a lot more effort but is still preferable to using the same password across all accounts or having to reset forgotten passwords every week.
  2. Choose one semi-difficult password for all accounts but insert a naming convention in the middle of the password to denote which account you are signing into. For example, if your password is L3tme1npleaz, your Gmail password could be L3tme1nGMAILpleaz. Your Amazon password could be L3tme1nAMAZONpleaz, and so on and so forth.
  3. When possible, choose a service that has two-factor authentication over one that does not. More than 150 applications currently implement two-factor authentication. 
Passwords don’t have to rule your life. You can lock them up behind a password manager and worry about remembering a single, slightly complex phrase instead of 27. You can relax knowing how well guarded your passwords are. And you can go ahead and burn that secret list of passwords you keep in your address book even though you’re not supposed to.

Do you have a favorite password manager? Or a method for creating and remembering unique passwords? Let us know in the comments below.

Posted: May 4, 2017
Malwarebytes Labs by Wendy Zamora
Last updated: May 3, 2017

Comments

Popular posts from this blog

New CEO Named at SF Fire CU

  In San Francisco, – SF Fire Credit Union has appointed Robert Kassab as its president and chief executive Officer. Kassab, who has served as the $1.6-billion credit union’s CFO and most recently as Interim CEO, will lead the organization as it builds on 75 years of community service and pursues an ambitious strategy for growth and member impact, the credit union said in a statement. Robert Kassab “SF Fire Credit Union has a 75-year legacy of doing right by its members, and I take that responsibility seriously,” Kassab stated. Kassab joined SF Fire Credit Union in 2022 as CFO, where he played a central role in strengthening the institution’s financial foundation and positioning the credit union for long-term growth. His appointment as CEO follows a period of interim leadership, during which he worked closely with the board to develop a strategic vision for the credit union’s future, according to SF Fire. An Institution That ‘Deserves Them Back’ “SF Fire Credit Union was built on ...

Crews Shares Vision For NCUA, Refuses To Enter Board Battle

By Ray Birch WASHINGTON—NCUA nominee John Crews used his Senate Banking Committee confirmation hearing Thursday to lay out an agenda centered on reducing regulatory burden for smaller credit unions, encouraging technological innovation and reviving the formation of new credit unions, while declining to weigh in on the legality of the NCUA's current one-member board because of pending litigation. Although much of the hearing was dominated by sharp questioning of fellow nominee Christopher Phelan over the economy, inflation, tax policy and President Trump's agenda, Crews' exchanges with senators offered insights into how he might approach regulating the credit union system if confirmed. The hearing proceeded despite questions on Capitol Hill over whether it would even take place following Wednesday's political turmoil surrounding President Trump's demand that Congress pass the SAVE America Act before he signs bipartisan housing legislation and the Senate's decisio...

NCUA Board Meeting Coverage: Here’s Where Deregulation Project Stands

  ALEXANDRIA, Va.—An update on NCUA’s ongoing Deregulation Project was provided during the Thursday board meeting. Offering the update was Amanda Parkhill, acting director of the agency’s Office of Examination and Insurance.“There’s a lot going on and we anticipate over 50 rulemaking guidance and policy actions as a result of the deregulation project and other efforts taken to reduce burden and streamline processes,” said Parkhill. “These cover a wide variety of topics from new,   innovative technology to long standing anti money laundering and consumer compliance requirements. Many of the actions we are working on involve coordination with other regulators to ensure that requirements are consistent among banks and credit unions.” Parkhill said 31 proposals have been made as part of the Deregulation Projects, two of which are still out for comment.  “We are in very stages of finalizing several of the proposed rules,” Parkhill said. adding that objective is to wrap up phas...

DC Round-Up

  HUD Makes ACU-Requested Change; Hearing on Payments Today; CU-Backed Candidate Wins in Utah WASHINGTON–The Department of Housing and Urban Development (HUD) has updated Federal Housing Administration (FHA) quality control requirements to allow greater flexibility and alternatives to appraisal field reviews in a change that had been requested earlier by a coalition of 10 trade groups, including America’s Credit Unions .  The new provisions took effect immediately when released in a Mortgagee Letter on June 23, . According to ACU, the change removes the requirement for mortgage lenders, including credit unions, to obtain appraisal field reviews on at least 10% of origination and underwriting quality control reviews.  “The change will make field reviews optional for appraisal quality control, maintain FHA’s core appraisal compliance framework, and give lenders the ability to tailor their review methods on a case-by-case-specific risk,” America’s Credit Unions said. “The r...

Healthcare Fraud Sweep

  The Justice Department has charged 455 defendants across 45 states and US territories in a $6.5B healthcare fraud crackdown , which officials described as the largest coordinated enforcement action in its history and the second-largest amount ever charged in a single operation (behind last year’s $14.6B operation). Authorities say the schemes targeted Medicare, Medicaid, and other healthcare programs through fraudulent billing, illegal kickbacks, opioid distribution, and telemedicine operations. Those charged include 90 licensed medical professionals, while 295 defendants are tied to over $500M in false Medicaid claims. Investigators also seized more than $127M in cash, vehicles, jewelry, and other assets tied to the alleged fraud. The two-week crackdown comes amid the Trump administration’s antifraud push, with expanded data-sharing efforts across agencies (scroll to see coordinated effort ). Experts estimate healthcare fraud costs t...

Sunday Reading - Underwater Kingdoms

Underwater Kingdoms   Coral reefs are underwater ecosystems made from the skeletons of hard coral colonies. Each colony is composed of multiple polyps called corals—animals with tentacles around a mouth at one end and sac-like bodies at the other that attach to a surface and secrete calcium carbonate for protection. Over thousands of years, these secretions accumulate to form habitats that support about 25% of marine species, even though they cover less than 1% of the ocean floor. >  The first coral reefs formed hundreds of millions of years ago. ( More , w/video) > Coral polyps are tiny animals whose mouths both consume food and expel waste. ( More ) > See how coral reefs get their color. ( More ) Known as the "rainforest of the seas," coral reefs are found in tropical and subtropical waters of more than 100 countries, wi...

AI Rapidly Reshaping How Consumers Discover, Compare & Choose Banking Products (But Trust Remains an Issue)

  Frank Diekmann May 26, 2026 SYDNEY — Artificial intelligence is rapidly reshaping how consumers discover, compare and select banking products, forcing financial institutions to rethink their digital marketing and customer acquisition strategies, according to a new report from Bain & Company .  The report, titled “How AI Rewrites the Rules of Brand Discoverability in Banking,” found that AI assistants such as ChatGPT, Claude and Google Gemini are increasingly acting as the first point of contact between consumers and banks, particularly in Australia, where consumers are using the technology to evaluate products, interpret fees and even prepare applications for loans and credit cards.  According to Bain & Company, the traditional banking sales funnel — once driven by branches, brokers, advertising and search engine rankings — is rapidly shifting toward AI-generated recommendations and responses. ‘Increasingly Influencing Choice’ “AI assistants increasingly influen...

47-Second Loan Décisions. Underwriting in Minutes. How AI is Revolutionizing Turnaround Time in Mortgage Lending

May 27, 2026 CU Today TORONTO–While AI has been deployed across a host of back office functions, on the consumer-facing side its promise is increasingly being seen in mortgage lending, where lenders are promising mortgage approval decisions in as little as 47 seconds, reporting that up to a third of inquiries are now being handled by chatbots, and slashing underwriting time to just minutes. Toronto-based TD Bank Group said it has also deployed its first agentic artificial intelligence system in mortgage lending, reducing the time required to prepare applications for underwriting from an average of roughly 15 hours to less than three minutes. According to a statement from TD Bank, the new AI model automates mortgage pre-adjudication — the process that occurs before a human underwriter reviews an application. The bank said the system classifies borrower documents, extracts and validates financial information, calculates income, performs policy and consent checks, identifies discrepancie...

NCUA Tells FICUs Crypto Trading is OK — If Big Exchanges Provide the Service

When it comes to reading between the lines of financial regulators’ advisory letters, tone matters. Take last week’s letter from the National Credit Union Administration (NCUA) which gave the federally insured credit unions (FICUs) it oversees permission to partner with digital asset providers to allow retail customers to buy, sell and trade in cryptocurrencies. Now compare it to the one issued by Comptroller of the Currency Michael Hsu’s agency to the national banks and federal savings associations it regulates a month earlier. On the surface, both said much the same thing: Financial institutions can provide cryptocurrency services (albeit with some notable differences: the OCC’s letter dealt with more back-end services, including custody services as well as holding and using dollar-pegged stablecoins for transaction settlement). Neither was enthusiastic. The NCUA’s letter said it “does not prohibit FICUs from establishing these relationships” — which is not as enthusiastic as “are a...

Retail sales in the United States jumped nearly 11% this holiday season

PURCHASE, N.Y.–Retail sales in the United States jumped nearly 11% this holiday season compared with the holiday period in 2019, the year before the pandemic upended the global economy, according to a new Mastercard analysis. The report, Mastercard SpendingPulse , showed an 8.5% increase in retail sales over the holiday season, defined as Nov. 1 to Dec. 24, compared with last year. The figures exclude automobile sales. According to Mastercard, sales in stores were up 8.1% compared with last year, while e-commerce sales were up 11%. Compared with 2019, before the pandemic brought about an explosion of online ordering, e-commerce sales jumped over 61%. Online sales made up 20.9% of all retail sales this year, the Mastercard SpendingPulse reported. In 2019, online sales accounted for just 14.6% of all retail sales, underscoring how the pandemic has accelerated the shift to e-commerce. Beating the Rush In a statement cited by the Times, Steve Sadove, senior adviser for Mastercard, sai...