All resources

Guide · For individuals

Passwords & 2FA done right — in one evening.

Two changes eliminate the most common ways accounts get taken over: a password manager and two-factor authentication. This is the complete setup, in the right order, with the traps marked. Pour a coffee — you'll be done tonight.

~8 min read Updated July 2026 One evening to do

Hi 👋 Here's the uncomfortable truth about passwords: the problem was never that yours is weak. It's that you have one good one and it's guarding forty doors. When any of those forty services gets breached — and eventually one does — that password gets tried against your email, your bank, and everything else, automatically, within hours. (If one already has been, and you're locked out right now, start with what to do in the first hour after a hack — then come back and do this so it doesn't happen again.) The fix isn't a cleverer password. It's making every door different and adding a second lock to the ones that matter.

That's two tools: a password manager (different key for every door, remembered for you) and two-factor authentication (the second lock). Set up in the right order, this is a single evening of work you never have to repeat.

Part 1 — The password manager

Pick one and don't overthink it

Any well-established, reputable password manager beats not having one by a mile. A dedicated manager (there are solid independent ones with free tiers) gives you the most flexibility across devices and browsers; the managers built into Apple, Google, and Microsoft accounts have also become genuinely good and are the lowest-friction choice if you live inside one ecosystem. The only wrong option is the reused password in your head.

Create one great master passphrase

This is now the only password you memorize, so make it long and make it yours: four or five random words with a small twist — something like copper-waffle-thunder-plum. Length beats complexity: a passphrase like that is far harder to crack than Tr0ub4dor! and far easier to type. Two rules: it must be new (never used anywhere before), and it never gets typed into anything except your password manager.

Don't skip this

Write the master passphrase on paper and store it somewhere you'd keep a passport. A recovery copy at home protects you from the one genuinely bad failure mode — locking yourself out of everything at once. A burglar interested in your sock drawer is not the threat model; a forgotten passphrase is.

Migrate the accounts that matter (not all forty)

Don't try to fix every account tonight — that's how this project gets abandoned. Change passwords on the big five now, and let the rest upgrade naturally as you log in over the coming weeks (the manager will offer to save and strengthen each one):

  1. Your main email — it resets everything else (more below).
  2. Banking and payment apps.
  3. Your Apple / Google / Microsoft account — it holds your device backups and often your other logins.
  4. Anything with your card on file that you use weekly.
  5. The password manager itself — that's your new master passphrase, done above.

Let the manager generate each new password — long and random. You'll never type them again, so there's no reason to keep them memorable.

Part 2 — Two-factor authentication

Two-factor authentication (2FA) means a stolen password alone isn't enough to get in — the attacker also needs something only you have. Not all second factors are equal, though. From strongest to weakest:

Rank Method The honest verdict
1 Passkeys Sign in with your face/fingerprint/device PIN — nothing to steal, nothing to phish. Where a service offers a passkey, take it; it can replace the password entirely.
2 Authenticator app Six-digit codes that change every 30 seconds, generated on your phone. Strong, free, works offline. The default choice for everything without passkeys.
3 SMS codes The weakest option — texts can be intercepted or your number hijacked — but still dramatically better than nothing. Use it only where it's the sole option offered.

Enable it in this order

Email first — always. Your inbox is the master key to your digital life: every “forgot password” link for every other account lands there. An attacker who owns your email owns everything downstream, which is why it gets the strongest protection before anything else. Then, in order: your password manager, your bank, your Apple/Google/Microsoft account, and your main social accounts (identity theft loves a trusted profile).

Save the recovery codes — offline

When you enable 2FA, each service hands you a short list of one-time recovery codes for the day your phone is lost or dead. Print them or write them down and keep them with that master-passphrase paper. Recovery codes stored in a note on the same phone they're meant to rescue are not recovery codes.

Three traps to step around

  1. Entering codes because someone asked. 2FA codes go into apps and sites you opened — never read one out on a phone call, never type one into a page you reached from a message. Anyone asking for a code is the attack. (This pairs with knowing how to spot a phishing email — the two guides cover each other's blind spots.)
  2. Guarding the vault with a weak lock. The password manager holds everything, so its master passphrase and its own 2FA matter more than any other. Don't reuse an old password there — ever.
  3. Stopping at setup. The manager will start flagging reused and breached passwords it now knows about. When it nags, spend the thirty seconds. That's maintenance done.

The one-evening checklist

  • Password manager installed on phone + computer, browser extension on
  • Master passphrase created (4–5 random words, brand new) and stored on paper
  • Big five migrated to generated passwords: email, bank, platform account, card-on-file services, the manager itself
  • 2FA on your email — passkey or authenticator app, not SMS if avoidable
  • 2FA on the password manager, bank, and platform account
  • Recovery codes printed and stored with the passphrase paper
  • Old reused password officially retired — it protects nothing anymore
The one-line version

One long passphrase you remember, a manager that remembers the rest, and a second lock on your email before anything else. That single evening removes the attacks that catch most people.

Keep going

Passwords locked down? That's move one.

The free Security Starter Kit walks you through all ten moves that lock down your digital life, ordered by protection-per-effort — plus one short, practical email a week.

Unsubscribe anytime. Explore more guides and resources.

Scroll to Top