Tech

7 rules for choosing a strong password for account security

Email, social networks, banking applications, and accounts on various gadgets have become a part of our daily lives

**7 rules for choosing a strong password for account security**

Accounts on email, social networks, banking applications, and various gadgets have become an integral part of our daily lives. Nevertheless, many people still use the same or easily guessable passwords for multiple accounts. This can cause other accounts to be compromised if one is breached.

According to current recommendations from the US National Institute of Standards and Technology (NIST), one of the most important factors in a password is its length. If a password is the sole means of protection, it is recommended to be at least 15 characters long. NIST prefers using a long and hard-to-guess password over forcing a mix of uppercase and lowercase letters, numbers, and special characters.

For example, instead of a short and complex-looking password like "P@ss12!", it may be safer to use a long passphrase made up of several unrelated words.

A separate password should be used for each account.

Google also recommends not reusing the same password across email, banking, and other important accounts. This is because if a password is stolen from one site, criminals can try it on other services as well.

Remembering dozens of different passwords is difficult.

For this reason, CISA and NIST recommend using password managers. Such software generates a long and random password for each site and stores them securely. The user, in turn, mainly remembers one strong "master password."

A password alone is not enough protection.

Two-factor or multi-factor authentication (2FA/MFA) should be enabled on important accounts. In this case, even if the password is stolen, additional confirmation is required to access the account. CISA and NIST recommend MFA as a measure that significantly increases account security.

If possible, it is advisable to use methods such as an authenticator app, a security key, or a passkey rather than an SMS code.

Google points to passkeys as a more phishing-resistant method. Microsoft also rates FIDO2-based passkeys as a phishing-resistant authentication tool.

A passkey is a login method using a cryptographic key stored on the device instead of a traditional password. It can be verified with a fingerprint, Face ID, Windows Hello, or a device PIN. Apple also describes passkeys as a technology more resistant to phishing attacks compared to passwords.

The screen lock of a phone and tablet is also important.

Official Android recommendations state that a PIN can consist of at least 4 digits, but a 6-digit or longer PIN is more secure. Biometric protection—unlocking via fingerprint or face—also provides additional security.

Another common habit is changing the password every month or every three months.

NIST does not recommend such mandatory periodic changes. A password should mainly be changed when there is a suspicion that it has been compromised, data has leaked, or the account has been breached.

Also, easily guessable combinations such as first name, last name, date of birth, phone number, 123456, and qwerty should not be used in a password.

NIST also requires services to compare new passwords against lists of known, commonly used, or previously leaked passwords.

In short, for a secure account, a long and unique password for each service, a password manager, and two-factor protection are the most important measures. On supported services, switching to a passkey helps protect the account from a number of risks associated with phishing and password theft.

Cookies on xabarchi

We use cookies to remember your language and theme, and to count how many people are reading right now — that count is anonymous, lasts only while your browser is open, and cannot be tied to you or to another visit. With your permission we also measure how the site is read: Microsoft Clarity, which records page views and on-page interactions, and our own count of returning readers. Nothing that recognises you across visits is measured until you accept.