Password management
None of this is expert advice. It's what people worked out for themselves, usually the hard way — what actually helped, and what they'd tell someone standing where you are. Take what fits and leave the rest.
If you only read a few
Memorize a small set of core passwords and write down only their first few letters as cues in notes.
It allows you to identify which password applies without writing the full secret.
- This method is not completely foolproof.
one person who lived it
- Use the entire memorable sentence as your password rather than just its first letters.2
- Hide master password cues in inconspicuous locations, such as draft emails or at the bottom of old shopping lists in phone notes.1
If you must store or email credentials, omit the word 'password' and its abbreviations to prevent discovery via search functions.
It prevents the file from being found through simple text searches.
- Also avoid writing 'username' if possible.
one person who lived it
Never reuse identical credentials across several critical online profiles.
A breach of one account exposes all others to risk.
3 people, independently
Use long passphrases consisting of random words or sentences rather than short strings of complex characters.
Length makes passwords harder to crack and guess than complexity alone.
3 people, independently
- Choose very long, non-dictionary strings of characters for maximum strength, acknowledging they will need to be stored rather than memorized.1
Back up your KeePassXC database file to a cloud service like Backblaze, and keep the decryption key or password in a physical location such as your wallet.
To ensure access if your house burns down.
one person who lived it
If you write down passwords, add a secret suffix that only your beneficiary knows.
It provides security in the event of a break-in.
one person who lived it
Avoid websites that send passwords in clear text during recovery.
Proper systems should only store hashes and not know the actual password.
one person who lived it
- Avoid websites that use security questions for password recovery.1
Avoid using serial numbers from watches or glasses as passwords.
Serial numbers may remain on warranty papers if the item is lost, can be unreadable without the glasses, or rub off over time.
one person who lived it
Avoid appending the site name or its first letters to a base password, as anyone seeing one password could determine your scheme and guess your others.
4 people, independently
9 more on this
Add a memorized phrase to passwords generated by a password manager to add a layer of security if the manager is compromised.
It protects accounts if the password manager itself is breached.
- Many users rely on auto-fill and may not manually enter the suffix.
one person who lived it
Do not combine old passwords to create new ones.
Reusing known components reduces security if the old password was compromised or is common.
one person who lived it
Do not store unencrypted password files on cloud services.
Cloud storage is someone else's computer; if compromised, all logins are at risk.
one person who lived it
Avoid biometric authentication for unlocking password managers if there is a risk of physical coercion.
A kidnapper could cut off fingers to access biometrics.
one person who lived it
Avoid SMS-based two-factor authentication.
It is insecure; it can be bypassed entirely or the message intercepted.
one person who lived it
In your inventory spreadsheet, note down website logins and password reminders instead of actual passwords to prevent exposure if viewed by others.
Prevents giving away passwords if someone else looks at it.
one person who lived it
Rely on the default security of major password managers, which require a login before granting access to saved credentials.
This ensures that even if someone accesses your computer, they cannot view or use your saved credentials without the master password.
one person who lived it
Enable two-factor authentication for sensitive accounts whenever possible.
3 people, independently
Be cautious about storing physical copies of passwords in books with abbreviations, as losing the book means losing access, and physical access to the device often compromises security anyway.
Losing the book prevents decryption; physical access to the device is already a critical failure point.
one person who lived it