Almost everything most people were taught about passwords is now officially wrong. Here is what replaced it, in the order it matters, for somebody who has never thought about it on purpose.
October 2026
The rules were followed and the outcome was worse. That is usually a sign the rules were aimed at the wrong thing.
The advice everybody absorbed in the 2000s — make it complicated, change it every three months, never write it down — produced exactly what you would expect. People invented one password with a capital letter and an exclamation mark, used it everywhere, and bumped the number at the end each quarter. The rules were followed and the outcome was worse.
The standards bodies have since admitted as much. The American institute whose guidance most of the world copies, NIST, now says the opposite in plain language: length instead of punctuation, no forced changes, and check passwords against lists of the ones already leaked. Most organisations have not caught up, which is why you still meet the old rules in the wild.
The words, first
Five terms cover nearly every conversation about this, and being fuzzy about them is what makes the subject feel harder than it is.
Two-factor authentication (2FA, or MFA). A second proof on top of the password: something you have, not something you know. A code from an app, a tap on a key, a message to your phone.
TOTP. The six digits that change every thirty seconds in an authenticator app. It is not sent anywhere — your phone and the website calculate the same number from a shared secret and the clock.
Passkey. A replacement for the password rather than an addition to it. Your device keeps a private key it never hands over and proves ownership with a fingerprint or a PIN. There is nothing to type, nothing to remember, and nothing that can be repeated somewhere else.
Phishing-resistant. Not a marketing word but a technical property: the method cannot be replayed on a fake site. A passkey is tied to the real address and simply refuses to work on a lookalike. A password is not phishing-resistant, and neither is a code you read off a screen and type in.
Recovery codes. The dozen one-time strings a service gives you when you switch on 2FA, for the day your phone is gone. They are the back door you leave yourself, and how you store them decides whether it is also somebody else’s.
Do: use a password manager, and stop remembering
This is the whole of the advice, and everything else is detail. One application holds every password, generates a different long one for each site, and fills them in for you. You remember exactly one password in your life: the one that opens it.
People resist this because putting everything in one place sounds like the opposite of safe. The arithmetic says otherwise. Without a manager you reuse passwords, because nobody can hold forty different ones; and reuse is how a leak at a shop you forgot about in 2014 becomes a break-in at your email today. That is the attack that actually happens, at scale, automatically.
There is also a benefit nobody mentions when selling these things. A manager fills in a password only on the address it belongs to. Land on a convincing copy of your bank and it will quietly do nothing — which tells you more than any amount of squinting at the address bar.
Do: make the one password you keep a long one
For the handful you still type yourself — the manager, the laptop, the phone — length beats cleverness. Four or five unrelated words are easier to remember and harder to break than Tr0ub4dor&3, and the guidance now says so outright: at least fifteen characters where the password stands alone, and no required mixture of symbols and capitals.
Unrelated is the operative word. A line from a song, a family name with a birth year, the dog and the street: those are in the lists. The strength is in the improbability of the combination, not in the substitution of a zero for an o, which every cracking tool has understood for twenty years.
Do: turn on a second factor where it counts
Not everywhere. On the accounts that can be used to take over the others: your email above all, then your password manager, your domain name, your hosting, your bank.
Email first, because every other account has a link marked forgot your password that ends in that mailbox. Whoever holds your email holds everything downstream of it, and no amount of care elsewhere makes up for it.
Use a passkey where the service offers one, an authenticator app where it does not, and text messages only as a last resort. Codes by text can be intercepted by persuading a phone shop to move your number to a new card — a tedious, thoroughly documented trick that works often enough to keep being used.
Older than the internet, by about two thousand years
None of this is a digital invention, which is worth knowing when a bank tells you that two-factor authentication is new and complicated.
From the Warring States period onwards, a Chinese military order travelled with a hufu: a small bronze tiger cast in one piece and then split down the middle. The commander in the field kept the left half, the capital kept the right. A messenger arriving with an order to move troops also carried the matching half, and the order counted for nothing until the two pieces fitted. A stolen order was useless; so was a stolen tally. You needed both, from two places, and the break itself was the proof, because no forger could reproduce a crack.
Rome had the domestic version. A tessera hospitalis was a token broken in two when a guest and a host parted, each keeping a half, so that years later — sometimes generations later, between people who had never met — the bond could be proved by producing the piece that fitted.
The oldest of the three is the one everybody knows without knowing it. In the book of Judges, the fords of the Jordan are held against fleeing Ephraimites, and every man crossing is asked to say the word shibboleth. The Ephraimites could not make the first sound and said sibboleth instead, and were killed for it. An authentication check on something you are rather than something you know, thousands of years before anyone drew that distinction — and the word survives in English as the name for exactly this kind of test. In Flanders, where I came from, there is a similar story: in 1302 Flemish rebels staged a nocturnal uprising and massacre against the French occupying forces and used “Schild en vriend” as a linguistic test for French speakers, who struggled to pronounce it.
Put beside that history, the twenty-odd years in which a single typed word was thought sufficient look like the anomaly rather than the norm. And a passkey is not a departure from the old idea, it is a return to it: your device holds one half, the service holds the other, and neither half is worth anything alone.
Don’t: the five that cause the actual damage
What goes wrong, in order of frequency
- The same password twice. One leak, anywhere, and every account that shares it is open. This is the big one; the rest are footnotes beside it.
- Passwords by email or message. A mailbox is a filing cabinet with no lock on the drawer, searchable, backed up, and readable by anyone who gets in once. If you must send one, send it separately from the username and have it changed on arrival.
- A shared login. The moment two people use one account, nobody can be removed without changing it for everybody, and the logbook can no longer say who did what. Give each person their own.
- Recovery that loops. Recovery codes inside the manager they are meant to recover; a recovery address at the same provider as the mailbox it protects; the login for your domain name arriving at an address on that domain. Every one of these works fine until the day you need it.
- Changing passwords on a schedule. Forced quarterly changes make people pick weaker ones and write them on paper by the screen. Change a password when there is a reason to think it leaked. Otherwise leave it alone.
Writing it down is allowed
The old rule against writing passwords down was written for an office where the threat was the colleague at the next desk. Your threat is a database of a hundred million stolen passwords being tried automatically against every site on the internet, and that attacker is not in your kitchen.
So: the password that opens your manager may be written on paper and kept where you keep your passport. Recovery codes should be on paper, in two different places, and not in the manager they would have to unlock. Paper does not get phished, does not sync, and cannot be copied from the other side of the world.
The part people forget: who owns the account
All of the above is about keeping strangers out. There is a second question, and for a small business it is the one that does real damage: whose name is on the account in the first place?
It is common, and quietly disastrous, for a domain name to sit in the account of the agency that registered it, for hosting to be billed to a developer who has moved on, for the only administrator of a website to be somebody who left two years ago. Nothing feels wrong until you want to change something — and then the answer is that you have to ask, and the person you have to ask is not answering.
The rule is short. The domain, the hosting and the mailbox stand in your name, with your email as the owner. Anyone who works on the site gets their own account inside yours, which you can withdraw. That way the worst case is an inconvenience rather than a hostage situation, and the day you part company nothing has to be handed over or trusted.
It is the same principle as everything else on this website. Renting the work is fine. Renting the keys is not.
If something does go wrong
Order matters more than speed. From a device you trust, change the password on your email first, then the manager, then the domain and the hosting. Sign out every other session — most services have a button for it. Only then start working out what happened. People instinctively investigate first, which means investigating while the intruder is still in the house.
And afterwards, the unglamorous part: check whether anything was added rather than taken. A forwarding rule on the mailbox, a new administrator on the website, a second recovery address. Those are what a patient intruder leaves behind, and they survive a password change.
The short version
A password manager, one long password to open it, a passkey or an app on your email and the four accounts that matter, recovery codes on paper in two places, and every account in your own name. That is an afternoon of work, once, and it covers nearly everything that actually happens to people.
Read the originals
- Digital Identity Guidelines: Authentication and Authenticator Management — NIST SP 800-63B-4
- Have I Been Pwned — to check whether an address of yours is in a known leak
- Fu — tallies of authorisation in ancient China
- Tessera — Illustrated Companion to the Latin Dictionary
- Passkeys — FIDO Alliance, on what replaces the password