Password hygiene that actually matters at 100 logins

Practical guides · About 7 minutes

A lot of password advice was written for a world where you had five accounts and typed each password from memory. At a hundred logins that advice doesn't just fail to scale — some of it actively makes things worse, by burning the attention you need for the handful of accounts that genuinely matter. This is a shorter list of things that are still true.

Reuse is the whole problem

If you take one thing from this page: uniqueness matters more than strength.

The dominant way accounts get taken over isn't someone cracking a password. It's credential stuffing — an attacker takes username and password pairs leaked from one breached site and tries them, automatically, against hundreds of others. It costs almost nothing to run and it works because people reuse.

A twelve-character password used on four sites is meaningfully worse than four eight-character passwords used once each. One breach at a site you'd forgotten you registered with becomes a breach of everything sharing that password.

This is also why the "strong password you can remember and use everywhere" strategy fails. Its strength is irrelevant, because it isn't being guessed — it's being copied from somewhere it leaked.

Where to start

Most password managers have a report that flags reused passwords. Run it. Sort the reused ones by blast radius, and fix the top of that list first. It's the highest-value hour you can spend on account security.

Length beats complexity

The composition rules many sites still enforce — one uppercase, one number, one symbol — were designed to stop humans picking password. They mostly succeeded at producing Password1!, which attackers' tools anticipate perfectly, because everyone applies the same substitutions in the same order.

What actually resists guessing is unpredictability, and the cheapest source of that is length. For anything you must type from memory, a passphrase of several unrelated words beats a short string of symbols on both counts: harder to guess, easier to type on a phone.

The important caveat is unrelated. Words drawn from a song lyric, a quote, or your own vocabulary aren't random — pick them by a genuinely arbitrary method, not by thinking of some.

For everything else — the ninety-odd passwords you never type — let the generator produce something long and meaningless. You're not going to read it, so there's no reason to make it pronounceable.

Rules that are mostly theatre

Scheduled rotation. Forcing a change every ninety days on accounts with no sign of compromise produces predictable increments — Spring2026! becoming Summer2026! — and trains people to treat password changes as bureaucracy. Modern guidance from major standards bodies has moved away from mandatory expiry for exactly this reason. Rotate on events instead: someone left, a credential was exposed, a breach was disclosed. The access-sharing guide lists the triggers worth acting on.

Security questions. Your mother's maiden name and the street you grew up on are, for most people, publicly discoverable — and they sit beside your password as an alternative way in, which makes them a weakening, not a strengthening. Where a service forces them, treat the answers as passwords: generate random strings and store them in your vault. There is no rule that the answer must be true.

Password hints. A hint useful enough to jog your memory is usually useful enough to help someone else. Leave them blank.

Banning paste. Not your rule to make, but worth naming: sites that block pasting into password fields make password managers unusable and push people toward short, typeable, reused passwords. When you hit one, use your manager's autofill rather than retyping, and consider it a mark against the vendor.

Spend your attention on the ones you type

With a manager doing the work, almost all your passwords become irrelevant to you personally — long, random, and never seen. The exceptions are the small number you type from memory, and those deserve real thought:

That's typically three or four passwords. Make each a long, genuinely random passphrase, never used anywhere else, and practise typing them until they're muscle memory. This is the small set where the old-fashioned advice — make it strong, memorise it, never write it down carelessly — still fully applies.

Breach monitoring is worth the ten minutes

You cannot tell from the outside when a service you use gets breached, and disclosure is often slow. Breach-monitoring services let you check whether an address of yours appears in a known leak, and most password managers now include this and will flag stored passwords that have appeared in a breach corpus.

Turn it on and act on the alerts. A reasonable response when something fires:

  1. Change the password on the breached service.
  2. Change it anywhere else you used it — and if the answer is "several places", that's the reuse problem announcing itself.
  3. Enable a second factor on that account if it wasn't already.
  4. Check the account for changes you didn't make: recovery addresses, forwarding rules, connected apps, API tokens.

That fourth step is the one people miss. An attacker who got in and left a mail forwarding rule or an API token behind still has access after you change the password. See the guide on long-lived tokens for why that matters more than it seems.

The identity matters as much as the password

At a hundred accounts, a surprising share of your friction isn't the password — it's not knowing which address you signed up with. Two habits fix this permanently.

Record the login identity in your vault entry, every time, even when it seems obvious. Future you will not remember whether that ad platform is under your personal address or the shared ops mailbox.

And where a provider supports address aliases or plus-addressing, consider a distinct address per service. It costs nothing, tells you exactly which service leaked your address when the spam arrives, and lets you cut off an alias without changing your real address. Check the provider handles it cleanly first — a few services reject addresses containing a plus sign at signup.

Shared and legacy accounts

Two categories break the rules above, and both need handling explicitly rather than hoping.

Shared logins can't be personal by definition. Get them into a shared vault collection with a documented reason, and rotate on every departure. The access-sharing guide covers the full ladder of alternatives — start there, because most shared logins turn out to be unnecessary.

Legacy accounts are the ones you'd forgotten: the trial you signed up for once, the tool a former colleague set up, the service you stopped using two years ago. They still hold data, they still have your reused password from that era, and nobody is watching them. When you build your inventory, close what you don't need. A closed account is the only one that can't be breached.

The short version

  1. Never reuse a password. This is the one that matters.
  2. Let a manager generate and store everything you don't type.
  3. Make the three or four you do type long, random, and memorised.
  4. Skip scheduled rotation; rotate on real events.
  5. Treat security questions as passwords and lie in them.
  6. Turn on breach alerts and actually act on them, including checking for tokens and forwarding rules.
  7. Record which identity signs in where.
  8. Close accounts you no longer use.

Related guides