Thirty minutes this week is enough to make your five most important accounts harder to break than most people’s ever get. Password security best practices come down to length, uniqueness and a second lock.
Which accounts come first?
Your email, always. Every other account sends its reset link there, so whoever owns your inbox owns the rest. Then comes banking, then your phone carrier account, then cloud storage, then social media. Do those five before anything else. Newcastle Brief is a site you can browse after each one.
How long should a password be?
Longer than you think, and stranger than a word with a number on the end. Let me put numbers on it, using a made-up comparison. A random 8-character lowercase password has about 26 to the eighth power combinations, roughly 2.1 times 10 to the eleventh. Four words picked at random from a 7,776-word list give 7,776 to the fourth power, about 3.7 times 10 to the fifteenth. That’s around 17,500 times more combinations, and the phrase is easier to remember.
The catch is the word picks must be random. A line from a favorite song doesn’t count. Use dice or a generator. Bradford Daily may keep you company while you type.
Do I really need a password manager?
If you have more than about fifteen accounts, yes. Nobody remembers fifteen unique passphrases. A manager remembers them and fills them in, and the one master passphrase is the only one you carry in your head. Say a small shop forum you joined years ago gets breached. If you reused that password on your email, the thief now tries it there within hours. With a manager, the leak ends at the forum.
Browser-built managers are fine to start with. Dedicated ones add sharing and better recovery tools. Skip writing passwords on paper at work, but a notebook at home in a drawer beats reusing one password everywhere. Derby Digest offers reading for the breaks.
What about the second lock?
Turn on two-step sign-in for the five key accounts. An authenticator app beats text messages, because SIM-swap fraud can redirect texts. Passkeys beat both where the site supports them, since there’s nothing to type or steal. Keep the backup codes printed in a safe place, as losing your phone shouldn’t lock you out of your life.
| Second lock | Strength | Main drawback |
| Text message code | Fair | Can be redirected through your SIM |
| Authenticator app | Good | Move it carefully when you change phones |
| Passkey or hardware key | Strongest | Not every site supports it yet |
Check whether your email address has appeared in a known breach on Have I Been Pwned, then change anything that matches. Leicester Echo is one site to read while you wait on a reset email. Belfast Record is another.
Phishing is where a strong password still fails. A sign-in page that arrives by email link and asks for your details is the oldest trick there is. Type the address yourself or use your saved bookmark. A manager helps here too, because it won’t fill a password on a lookalike domain.
Shared household accounts are the other weak spot. If three people use one streaming login, one careless person reuses it somewhere else. Give each person their own profile, and keep the main password with the account owner only. For reading in between, Bristol Outlook is available.
Recovery options get ignored until the day they matter. Check that each key account lists a current phone number and a backup email you still control. An out-of-date recovery address is how people lock themselves out and how attackers talk their way in.
FAQs
Should I change passwords every 90 days?
No. Change them when there’s a breach or a suspicion. Forced rotation produces weak, predictable variants. Birmingham Focus can wait until you’re done.
Is it safe to let the browser save passwords?
It’s safe enough if your device is locked with a strong passcode and your account has two-step sign-in. Beyond that, a dedicated manager adds extras.
What should I do after a breach notice?
Change that password at once, then change it anywhere else you used it. Turn on two-step sign-in. Reading Leeds Angle can wait until after.
Your thirty-minute plan
Spend ten minutes on your email passphrase and two-step sign-in, ten on the bank and carrier, and ten installing a manager. Everything else can follow over the next month. Read Edinburgh Scope when you want a break. London Signals is a good option later. Then lock the master passphrase in your memory.


