Brilliance in the Basics #2: Diverse Passwords for Every Account

One reused password can turn a single breach into multiple account takeovers. Learn how unique passwords, a password manager, MFA, and passkeys help protect your digital life.

A retailer you used once suffers a breach. An attacker obtains your email address and password, then tries that combination against your email, banking, and work accounts. If you reused the password, a problem at one business can become a problem across your digital life.

This is why password diversity matters. Every account that uses a password needs its own independently generated password. Not a familiar phrase with a different number. Not one password for shopping and another shared across everything important.

The practical solution is not better memorization. It is a repeatable system: use a password manager, replace reused credentials, enable multifactor authentication, and adopt passkeys where available.

What “Diverse Passwords” Actually Means

Diversity means independence: knowing one password should not help someone predict another. Attackers routinely test stolen credentials against other services, an attack commonly called credential stuffing. NIST’s authentication guidance identifies password reuse as the condition that makes this attack possible.

Consider this pattern:

  • RiverTrail!Email26
  • RiverTrail!Shopping26
  • RiverTrail!Bank26

These are illustrations, not passwords to use. They differ, but they share an obvious recipe. Once one is exposed, the others become easier to guess. Research into reused and modified passwords shows why predictable transformations are not a reliable defense.

A complex password reused across accounts creates a shared point of failure. Independent passwords help contain the damage.

Uniqueness does not prevent phishing, malware, or every account takeover. It prevents a stolen password from automatically becoming a key to unrelated accounts.

Make Passwords Long, Random, and Unique

For everyday use, instruct your password manager to generate at least 16 characters wherever the service permits. CISA recommends long, random, unique passwords and offers a passphrase of five to seven unrelated words as another option in its strong-password guidance.

For a password you must remember, such as a vault’s primary password, use randomly selected words rather than a quotation, personal story, or familiar expression. Never adopt a password example published in an article.

Current standards also distinguish system requirements from personal recommendations. NIST SP 800-63B-4 requires covered verifiers to set a minimum of 15 characters for passwords used as the sole authentication factor. Passwords used only within multifactor authentication may have an eight-character minimum. That exception is not a recommendation to shorten your passwords.

NIST also rejects mandatory character-mixture rules and routine password changes without evidence of compromise. If a website requires symbols or capitals, let your generator comply. Do not confuse decorating a predictable password with making it strong.

A Practical Plan to Eliminate Password Reuse

1. Choose a manager that fits your actual devices

A browser’s built-in manager or a dedicated password-management app can make unique passwords manageable. The right choice should work reliably across the devices and browsers you use. For work accounts, follow your employer’s approved approach.

Compare encryption, MFA support, recovery options, security updates, portability, and secure sharing. The UK National Cyber Security Centre’s password-manager buyers guide provides a useful evaluation framework.

The tradeoff is concentration: a manager holds valuable credentials in one place. Protect its login with a strong, unique password or its supported stronger authentication method, enable MFA where offered, and understand recovery before filling the vault. Keep essential recovery materials somewhere secure that does not depend entirely on opening that same vault.

If you migrate managers, treat exports carefully. Some contain readable, unprotected passwords. Follow the provider’s migration instructions, avoid unnecessary copies, and remove temporary exports when finished.

2. Prioritize accounts that control other accounts

First secure the manager you will use. Then work through accounts in a risk-based order:

  • Primary email: inbox access may allow an attacker to reset passwords elsewhere.
  • Device and synchronization accounts: these may control access to stored credentials and recovery services.
  • Financial and sensitive accounts: banking, payments, healthcare, and accounts holding important documents.
  • Work accounts: coordinate changes with organizational requirements.
  • Everything else: shopping, social media, subscriptions, and forgotten services.

This is a suggested workflow, not a universal ranking. An actively compromised account takes priority. The FTC’s account-recovery guidance explains why protecting email is especially important.

3. Change the password at the service

Editing a password-manager entry does not change the account’s password. The service must accept the new credential.

  • Open the official app or navigate directly to the service’s website.
  • Find its password-change settings.
  • Generate an independent password that meets its requirements.
  • Submit the change and confirm that the service accepts it.
  • Save the accepted password in the correct vault entry.
  • Confirm that the saved credential works before moving on.

Check the account name and website address when saving. Duplicate entries and outdated credentials can turn a straightforward cleanup into a lockout problem.

4. Use warnings as a work list

If your manager flags reused, weak, or exposed passwords, work through those findings. Saving an existing reused password improves convenience; replacing it resolves the reuse.

Do not limit the cleanup to exact duplicates. Replace passwords built from the same recognizable formula, too. For accounts you no longer need, consider closing them through the provider’s official process.

Add MFA—and Understand Where Passkeys Fit

Unique passwords limit one kind of exposure. Multifactor authentication adds another layer when a password is stolen. Look under security settings for “multifactor authentication,” “two-factor authentication,” or “two-step verification.”

CISA recommends phishing-resistant MFA where available. Security keys and appropriately implemented passkeys provide stronger phishing protection than methods that require typing a code. Authenticator-app codes remain useful, but attackers can trick people into entering them on fraudulent sites. SMS has additional weaknesses, though it is generally better than password-only access.

Passkeys replace typed passwords with cryptographic credentials tied to a service. You typically approve their use through a device PIN or biometric check. According to the FIDO Alliance’s passkey guidance, the main deployment choices involve different convenience and recovery considerations:

  • Synced passkeys: available across supported devices through a provider. Protect that provider account and understand its recovery process.
  • Device-bound passkeys: remain on a particular device, including a security key. Arrange a supported backup or recovery method before relying on one device.

Before replacing a phone or computer, check how you will retain access. If an account keeps a password as a fallback, that password still needs to be unique. Also secure recovery email, phone numbers, and backup codes; stronger sign-in does not eliminate recovery risk.

If a Password Is Exposed, Break the Connection

Do not add a digit to an exposed password. Replace it with an independently generated one, then replace it everywhere else it was reused. Address predictable variations as well.

If someone has taken over the account, use the provider’s recovery process. From a trusted device:

  • Change the password and sign out other sessions where supported.
  • Review recovery contact details and enrolled authentication methods.
  • Enable or restore MFA.
  • Check email forwarding rules and messages the attacker may have sent.

The FTC recommends these post-compromise checks because changing a password alone may leave other access routes intact. If you suspect malware, address it before entering replacement credentials on the affected device.

Your Diverse-Password Checklist

  • Every password-based account has an independently generated password.
  • Passwords contain at least 16 characters wherever supported.
  • No accounts rely on variations of a shared phrase.
  • A password manager stores current, verified credentials.
  • The manager’s login and recovery arrangements are protected.
  • Primary email has a unique password and MFA.
  • Reused, weak, and exposed-password warnings have been reviewed.
  • Passkeys or phishing-resistant MFA are enabled where practical.
  • Recovery details are current, and backup methods are accessible securely.

Make the Basics Repeatable

Password diversity is not a test of memory or creativity. It is a way to stop one compromised credential from spreading trouble across your accounts.

Start today with your primary email: replace any reused password, enable MFA, and verify recovery options. Then work through the remaining accounts using the same process. The objective is not a collection of clever passwords. It is a sustainable system in which every account has its own protection.

Browse all insights · Contact Bart McDonough