Services Method About Archive Contact

Secure passwords: a step-by-step guide, common mistakes and two-factor authentication (2FA)

In short. A secure password is long (at least 15 characters, ideally 20), random (generated by software or made of randomly chosen words) and unique (used for one account only). Store it in a password manager and protect important accounts with two-factor authentication, preferring apps, security keys or passkeys to SMS.

In my work as an OSINT analyst I often see how the accounts of individuals and small businesses get compromised. There is almost never a brilliant hacker behind it: usually it is a reused password that ended up in an old data breach, or a password built from information anyone can find online. The good news is that a few rules, applied methodically, remove most of the risk.

This guide follows the current recommendations of the US NIST (SP 800-63B, revision 4, published in 2025) and of Swiss Crime Prevention. Where the two sources differ, I point it out.

Note: the software mentioned is given as examples, not sponsorship. Choose according to your needs and always check the provider's reputation.


What makes a password secure

A password is secure when someone trying to guess it cannot succeed either by automated attempts or by deduction. That depends on three features:

Feature Why it matters Rule of thumb
Length Every extra character multiplies the number of possible combinations At least 15 characters; 20 or more for generated passwords
Randomness A long but predictable password (a quote, a date, a name) still falls Generated by the password manager or made of randomly chosen words
Uniqueness If you reuse a password, a breach of one site opens all the others A different password for every account

The rules that have changed

Much of the advice you have heard for years is now considered outdated. NIST, in revision 4 of its guidelines, states that services:

  • must not impose composition rules, such as requiring upper-case letters, digits and symbols;
  • must not require periodic password changes, but must force a change if there is evidence of compromise;
  • must check new passwords against a list of common or already compromised passwords;
  • must allow passwords of at least 64 characters, pasting, and the use of password managers;
  • must not use hints accessible to anyone, or security questions.

Swiss Crime Prevention still recommends at least 12 characters mixing digits, upper- and lower-case letters and special characters. For the user, the two are not in conflict: if your password manager generates 20 random mixed characters, you satisfy both.

Length versus complexity: the numbers

The strength of a random password is measured in bits of entropy: each extra bit doubles the number of guesses needed. Here is a comparison, valid only if the characters or words are truly chosen at random:

Type of password Example structure Approximate entropy
8 random mixed characters k7#Rq2!m about 52 bits
12 random mixed characters T9v!eQ2#pLw4 about 79 bits
16 random lower-case letters qmzvhtrkpwnalbxe about 75 bits
6 random words from a 7,776-word list shadow-teacup-beacon-five-fog-wheel about 78 bits
20 random mixed characters generated by the password manager about 131 bits

The lesson: a passphrase of six random words is worth as much as twelve random mixed characters, but it is far easier to remember. It is the ideal method for the one password you really have to memorise.


How to create a secure password in 8 steps

Step 1: take stock and start with critical accounts

You do not need to fix everything in one afternoon. Start with the accounts that, if compromised, open the door to all the others:

  1. Your main email account: that is where the links to reset every other password arrive.
  2. Your phone account (Apple, Google or Microsoft): it holds backups, photos, contacts and often saved passwords.
  3. E-banking and payments.
  4. The password manager, once you have chosen one.
  5. Social media and work accounts.

Step 2: choose a password manager

A password manager is software that generates passwords, stores them encrypted and fills them in automatically. You remember only one master password.

Type Examples Advantages Things to consider
Built into the system or browser Apple Passwords, Google Password Manager Free, already installed, simple Most convenient if you always use the same ecosystem
Dedicated, cloud-synced Bitwarden, 1Password, Proton Pass Works across all devices and browsers, family sharing Check reputation, independent audits and costs
Local, no cloud KeePassXC The encrypted file stays under your control Backup and syncing are up to you

Whichever you choose, protect access with a strong master password and with two-factor authentication.

Step 3: create the master password using random words

The master password is not stored in the password manager, so it must be strong and memorable.

  1. Use a word list designed for this purpose, such as the Diceware lists, or your password manager's passphrase generator.
  2. Draw 5 or 6 words at random, with dice or the generator, not by choosing them yourself. The human brain is very bad at generating randomness.
  3. Join them with a separator: shadow-teacup-beacon-five-fog-wheel.
  4. Repeat it for a few days until you know it by heart.

Alternatively, Swiss Crime Prevention suggests using the initials of a personal sentence, including punctuation and numbers. This works, but only if the sentence is not known or guessable: no quotations, song lyrics or mottos.

Step 4: generate a random, unique password for every account

For every other account, use the password manager's generator: 20 characters or more, with every character type the site allows. You do not have to remember them, so there is no reason to make them shorter.

If a site imposes a low maximum length, use the maximum allowed and turn on the second factor.

Step 5: turn on two-factor authentication

Start with the critical accounts from step 1. You will find the full procedure in the dedicated chapter below.

Step 6: check whether your credentials have already been breached

  • On Have I Been Pwned you can check whether your email address appears in a known data breach. Enter only your email address, never your password.
  • Many password managers automatically flag passwords that are weak, reused or found in known breaches.
  • Every exposed password must be changed immediately, on that site and on every other site where you reused it.

I described a real case, with the steps to follow, in the article on the Ricardo data breach.

Step 7: secure account recovery

An account is only as secure as its recovery procedure.

  • Update your recovery email address and phone number.
  • Save the backup codes for your second factor: printed and kept somewhere safe, or in your password manager.
  • Security questions: if a site insists on them, do not give true answers. Your mother's maiden name or your first school can often be found online. Answer with a random string and store it in your password manager.
  • Plan for the unexpected: some password managers let you designate an emergency contact. Consider this as part of estate planning too.

Step 8: maintain the system without stress

  • Do not change passwords on a schedule. Change them when there is a reason: a breach, a lost device, a suspicious login, a password shared with someone who should no longer have it.
  • Once a year, review your password manager's security report and close accounts you no longer use.
  • Keep your operating system, browser and apps up to date: many compromises start from an unpatched device, not a weak password.

The 12 most common password mistakes

# Mistake Why it is dangerous What to do instead
1 Reusing the same password When a site is breached, attackers automatically try the same credentials on email, banks and social media (credential stuffing) A unique password for every account
2 Using personal data Children's and pets' names, birth dates, favourite team and number plate can often be found online Random passwords with no link to you
3 Predictable substitutions P@ssw0rd or M4r1o are among the first variants cracking tools try Length and randomness, not tricks
4 Sequences and common words 123456, qwerty and password remain at the top of breached-password rankings The password manager's generator
5 Incremental variations Lugano2025! becoming Lugano2026!: anyone who knows the old one can guess the new one A brand-new random password when a change is needed
6 Writing passwords down in plain text Sticky notes under the keyboard, a "passwords.xlsx" file, phone notes, emails to yourself An encrypted password manager
7 Sharing via chat or email The message stays in copies, backups and on both people's devices The password manager's sharing feature; then change the password
8 Answering security questions truthfully The real answer is often easier to find than the password Random answers stored in the password manager
9 Typing your password after clicking a link A well-made phishing page collects your password and even your second-factor code Open the site by typing the address or from a bookmark; prefer passkeys
10 Ignoring breach alerts Exposed credentials are tried automatically, often soon after a breach Change the password at once and check other sites
11 Under-protecting your main email Whoever controls your email can reset almost all your other passwords Your strongest password and best second factor belong here
12 Blindly trusting strength meters Many meters reward Summer2026! because it contains every character type Judge by length and randomness, not the coloured bar

How an OSINT analyst reads other people's passwords

When I assess a company's digital exposure, with its consent, one of the first things I do is collect what is public about key people: family members' names, pets, important dates, teams, holiday spots, old email addresses. No unlawful access is needed: social media profiles, articles, registers and photos are enough.

With this information, anyone can build a list of plausible passwords. Criminals do exactly the same work, only without consent. That is why mistake number 2 matters so much: if a password means something to you, it means something to whoever is watching you.


Two-factor authentication (2FA): the complete guide

What 2FA is

Two-factor authentication asks, in addition to your password, for a second proof of identity from a different category:

Factor What it is Examples
Something you know A secret Password, PIN
Something you have An object in your possession Phone with an app, security key, card
Something you are A physical characteristic Fingerprint, face recognition

If someone steals your password, they cannot get in without the second factor. The term MFA (multi-factor authentication) is used when there are two or more factors.

2FA methods compared

Method How it works Security Weak points
SMS Code sent by text message Low, but better than nothing SIM swapping, phishing, network coverage
Email Code or link sent by email Low If your email is compromised, the second factor falls too
Push notification You approve the login in the service's app Medium Notification bombing to wear you down until you approve
Authenticator app (TOTP) 6-digit code generated on your phone, changing every 30 seconds Good Can still be stolen through a real-time phishing page
Physical security key (FIDO2) USB or NFC key you touch Very high, phishing-resistant Cost; you need at least two, one as a backup
Passkey Cryptographic credential on your device, unlocked with face, fingerprint or PIN Very high, phishing-resistant Not every service offers it yet; recovery needs planning

Why some methods are "phishing-resistant". FIDO2 keys and passkeys are cryptographically bound to the exact address of the site. On a fake site they simply do not work, even if you do not notice the deception. With SMS and TOTP apps, by contrast, you read a code and type it in yourself: if you type it on the wrong site, the attacker can use it immediately. That is why NIST considers passwords not phishing-resistant and requires more sensitive services to offer at least one option that is.

How to turn on 2FA, step by step

  1. Install an authenticator app on your phone, or get two security keys.
  2. Go to the account's security settings, in the "Security", "Sign-in" or "2-Step Verification" section.
  3. Choose the strongest method available: passkey or security key first, then an authenticator app, and SMS only if there is no alternative.
  4. Scan the QR code with the app, or register the key.
  5. Enter the verification code to confirm.
  6. Save the backup codes somewhere safe straight away.
  7. Register a second, backup method: a second key, a second device or the backup codes.
  8. Test it: sign out and back in, to make sure everything works before you need it.

The most common 2FA mistakes

  • Giving the code to someone. No bank, customer service or police force will ever ask you to read out a login code over the phone. Anyone who asks is a fraudster, always.
  • Approving a notification you did not request. If a login request arrives while you are not signing in, reject it and change your password at once: someone already knows it.
  • Not saving backup codes. Losing your phone without backup codes can mean losing access to the account for weeks, or for good.
  • Using email as the second factor for that same email account.
  • Thinking 2FA makes a good password unnecessary. The two layers work together: 2FA does not protect you if you hand over the code on a phishing page.

Passkeys: life after passwords

Passkeys are the standard that the major providers and many services are converging on. They work like this:

  • when you register, your device creates a pair of cryptographic keys: the private key stays on the device or in your password manager, the public key goes to the site;
  • to sign in, you unlock the passkey with face, fingerprint or PIN;
  • there is nothing to type, so nothing to steal with a fake page.

In Switzerland the direction is clear too: AGOV, the login for public authorities' online services, works without a password, using the AGOV access app or a FIDO security key, and recommends registering both methods and keeping the recovery code.

My practical advice: turn on passkeys wherever they are available, but keep a strong password and the recovery codes in your password manager, because the recovery procedure remains the sensitive point.


For companies and professional practices

The same rules apply to a business, with three additions:

  • A business password manager with controlled sharing, instead of shared files and chat messages.
  • Mandatory 2FA for email, remote access, accounting and system administration.
  • Staff training: most incidents begin with a well-written email and a person who trusts it.

Assessing how much information about your staff is public, and how easy it would be to build a credible attack against you, is one of the services I describe in the article on what an OSINT analyst does.


Final checklist

Done? Action
☐ I have chosen a password manager and protected it with a passphrase of 5 or 6 random words
☐ My main email, phone account and e-banking have unique passwords of 20 characters or more
☐ I have turned on 2FA for critical accounts, preferring passkeys, keys or apps to SMS
☐ I have saved the backup codes somewhere safe
☐ I have checked on Have I Been Pwned whether my email address appears in known breaches
☐ I have changed every reused or exposed password
☐ I have replaced true answers to security questions with random ones
☐ I know that nobody has the right to ask me for a login code

In short

Password security does not mean memorising dozens of unreadable strings. It means one good passphrase to remember, a password manager to do the rest, a second factor on the accounts that matter, and a healthy distrust of anyone asking for codes and of links arriving by email.

If you want to understand how exposed you or your company are online, or if you have suffered unauthorised access and need to reconstruct what happened, you will find the details among my services. The first consultation is free and confidential.


Main sources: NIST, Special Publication 800-63B "Digital Identity Guidelines: Authentication and Authenticator Management", revision 4 (2025); Swiss Crime Prevention, leaflet "Sicurezza online e password complesse" (2025), produced with the Lucerne University of Applied Sciences and Arts and "eBanking – but secure!"; official AGOV website (agov.ch); Have I Been Pwned. Entropy values assume characters or words are chosen at random.

Frequently asked questions

How long should a secure password be?

The US NIST guidelines (SP 800-63B, revision 4) require at least 15 characters for a password used on its own and at least 8 when it is combined with a second factor. Swiss Crime Prevention recommends at least 12 characters. In practice: use 20 characters or more for passwords generated by your password manager, and a passphrase of 5 or 6 random words for the one you need to remember.

Is a complex password better than a long one?

Length matters more than complexity, provided the password is random. A passphrase of six randomly chosen words is as strong as 12 random mixed characters and much easier to remember. Swapping letters for symbols, as in P@ssw0rd, does not help: cracking tools know these substitutions.

Should you change your password every three months?

No, not if the password is strong and unique. NIST recommends against forcing periodic changes, because they lead to ever weaker and more predictable passwords, such as Lugano2025! becoming Lugano2026!. You should change a password immediately, however, if you suspect it has been compromised.

Are password managers safe?

A good password manager encrypts your passwords with a key derived from your master password, and for most people it is far safer than reusing a few passwords or writing them down. The weak point becomes the master password: it must be long, unique and protected by a second factor.

Is two-factor authentication by SMS secure?

It is much better than no second factor, but it is the weakest method: the code can be intercepted through SIM swapping or stolen through a phishing page. Where possible, choose an authenticator app, a physical security key or a passkey.

What is a passkey and does it replace passwords?

A passkey is a cryptographic credential stored on your device or in your password manager and unlocked with your fingerprint, face or PIN. It cannot be typed into a fake website, so it resists phishing. Many services already offer it as an alternative to passwords; for now it is still wise to keep a strong password as a fallback.

Address

Via Dante Alighieri 5, 6830 Chiasso (Svizzera)

Hours

Mon–Fri, 9am–7pm · we reply within 24 business hours

Confidentiality

Every request is handled with the utmost confidentiality, without exception.

Write us an email
info@minerva.agency Email info@minerva.agency

For maximum confidentiality we invite you to write from a Proton Mail account: communications between Proton addresses are end-to-end encrypted, so no one — not even the provider — can read their content. Opening one is free. proton.me

No contact forms, no data passing through intermediate servers: you write to us directly, from your own mail client.