Accounts
Passwords: fewer rules, better habits
Length beats complexity, reuse is the real danger, and a manager solves both. A practical guide to passwords, two-step authentication and passkeys.
Updated 8 min readqikfox
The short answer
A strong password is long, unique to one account, and stored in a password manager rather than remembered. Reuse is the single biggest weakness, because one breached site then unlocks the others. Adding two-step authentication, or a passkey where offered, matters more than adding symbols to a short password.
Key points
- Length contributes more to strength than substituting characters does.
- Reuse converts one site's breach into a break-in on every other account.
- A manager makes uniqueness practical and quietly resists phishing pages.
- Two-step authentication means a stolen password alone is not enough.
- Passkeys remove the shared secret entirely and cannot be phished.
Why the old rules failed
For years, guidance demanded symbols, capitals, digits and quarterly changes. People responded rationally: they built one password that satisfied the rules, then adjusted it slightly whenever forced. The result was millions of predictable variations and no improvement in security.
Modern guidance dropped forced rotation and character mandates for exactly that reason, and focuses instead on length, uniqueness and detecting compromise. The rules got simpler because the simpler rules work better.
Length and uniqueness, in that order
Guessing attacks work through possibilities, so every additional character multiplies the work required. A memorable sequence of several unrelated words is both long and typeable, which is why passphrases beat short cryptic strings.
Uniqueness matters even more. When a site is breached, the stolen credentials are tried automatically across other services - email, retail, banking, workplace tools. If your password is unique, that attempt stops at the breached site. If it is reused, one incident becomes several.
- Prefer a passphrase of several unrelated words over a short complex string.
- Never reuse a password, especially for email, which resets everything else.
- Change a password when a service reports a breach, not on a schedule.
- Keep recovery details current - they are the real key to the account.
Why a manager is the practical answer
Nobody can remember dozens of long unique passwords, and writing them in a document defeats the purpose. A password manager generates and stores them behind one strong passphrase, and fills them for you.
The security benefit people notice least is the most useful: a manager fills credentials based on the domain, so it declines to autofill on a lookalike phishing page. That silent refusal is often the first clue that a page is not what it claims.
The trade-off is real and worth stating: your manager becomes a single high-value target. Protect it with a long unique passphrase and two-step authentication, and keep an offline record of recovery codes.
Two-step authentication and passkeys
Two-step authentication requires something beyond the password. An authenticator application generating codes is a solid default. SMS is better than nothing but weaker, because phone numbers can be transferred away from you. Hardware keys are the strongest option and worth it for accounts that control others.
Passkeys go further by removing the shared secret. Your device keeps a private key, the service keeps a public one, and authentication happens with a biometric or device unlock. There is nothing to type, so there is nothing to phish. Where a service offers passkeys, they are the best available choice.
If you only do three things
Give your email account a long unique passphrase and strong authentication, because email is the reset path for everything else. Install a password manager and let it replace reused passwords gradually, starting with financial and work accounts. Turn on passkeys or an authenticator app wherever they are offered.
That is the majority of the benefit for a modest amount of effort, and it does not require becoming an enthusiast about the subject.
Questions and answers
Related qikfox pages
Security at qikfox
Account and device security principles.
Recognising phishing pages
How credentials are usually taken.
Trust at qikfox
How we handle your account data.
Help Center
Account and sign-in questions.
Back to Guides · Written and reviewed by the qikfox editorial team. Published .
Put the advice into practice
qikfox Safe Browser applies most of what this article describes by default, and works alongside qikfox Search, Antivirus and VPN.