Section
Passwords And Authentication
Guides, explainers, and practical reads updated regularly. test
All Articles
How to build a passphrase you will actually remember
NCSC's three-random-words method, checked against the length floors NIST set in July 2025, and where a memorised phrase stops being enough.
Single sign-on and multi-factor authentication solve different problems
One reduces how many passwords exist; the other adds a second check. They are not alternatives — but the factor you add matters enormously.
Memorised passphrases against generated passwords
A phrase you can remember and a random string you cannot are for different accounts. Here is where the line falls, and why length settles…
Sorting your accounts by what they unlock
Not every account deserves the same effort. A short exercise to find the few that everything else depends on, and protect those properly.
Your fingerprint is not replacing your passcode
On a modern phone the screen-lock credential protects the encryption key. The fingerprint sensor is a convenience layer sitting on top of it.
How account recovery gets used against you
Recovery routes are designed to work when you have lost everything, which is exactly why attackers aim at them instead of your password.
Setting up a password manager without locking yourself out
CISA recommends one. The setup order matters, because the failure people actually hit is losing access to the vault, not having it breached.