Password Security Best Practices: Beyond 'Use Strong Passwords'

Password advice keeps changing, and for good reason. This guide explains what modern guidance actually says: why passphrases beat complex passwords, how password managers and MFA do the heavy lifting, where passkeys are heading, and how to respond when credentials leak.

Why Password Advice Keeps Changing

For years, the standard advice was: mix upper and lowercase letters, add numbers and symbols, and change your password every 60 to 90 days. That advice came from an era of manual guessing attacks and short password limits — and it turned out to be counterproductive.

When the U.S. National Institute of Standards and Technology (NIST) updated its digital identity guidelines (SP 800-63B) in 2017, it dropped both forced periodic rotation and mandatory complexity rules. The reason is human behavior: complexity rules produce predictable substitutions — “P@ssw0rd1” — that modern cracking tools handle easily, and forced rotation pushes people toward weaker passwords they can actually remember. Modern guidance emphasizes three things instead: length, uniqueness, and multi-factor authentication.

Passphrases vs Complex Passwords

When attackers guess passwords at scale, length is the strongest defense. A passphrase made of four or more unrelated words — for example, correct horse battery staple — is far harder for automated tools to crack than Tr0ub4dor&3, and much easier to remember.

The catch: the words must be genuinely random. Use a random word generator (the “diceware” method), not song lyrics, quotes, or phrases from your personal life, which attackers' dictionaries include. Many services accept spaces; where they do not, hyphens or simply running the words together works. Aim for at least 12–16 characters, and longer is better. Added symbols contribute little — length and unpredictability do the real work.

Password Managers

Reuse is the actual problem. When you reuse a password, one breached site turns into many compromised accounts. A password manager solves this by generating a unique random password for every site and storing them in an encrypted vault you unlock with a single strong master passphrase.

Choose a reputable manager — the built-in managers in major browsers and operating systems are fine for individuals, and dedicated apps offer more for teams — that encrypts your vault locally. Protect the vault itself with MFA, and treat the master passphrase as the one credential you memorize and never reuse anywhere.

For teams, password managers add shared vaults, per-role access, breach alerts, and smooth offboarding: revoking an employee's vault access removes dozens of accounts in one step instead of dozens.

Multi-Factor Authentication

MFA is the single highest-impact control available. With it, a stolen password becomes nearly useless, because the attacker also needs your second factor. Prefer authenticator apps (TOTP codes) or hardware security keys over SMS, since text messages can be intercepted through SIM-swapping attacks. Some services push MFA prompts to an app or device, which is also strong.

Treat MFA as mandatory for business accounts — email, financial, cloud, domain, and administrative accounts at minimum. Convenience arguments fade quickly when you consider that a single unprotected mailbox is often all an attacker needs to reset passwords across your other services.

Passkeys: The Future

Passkeys, built on the FIDO2/WebAuthn standards, replace passwords with cryptographic key pairs. Your device holds the private key — often synced through your Apple, Google, or Microsoft account — and websites only ever see a signed challenge, never a secret. That makes passkeys phishing-resistant by design: a fake login page cannot harvest something that is never typed or transmitted.

Support has grown steadily across major platforms, and password managers increasingly store passkeys as well. For most users, the practical advice is simple: where a service offers passkeys, use them. They remove both the memorization burden and the phishing risk, which is exactly what a good security control should do.

Handling Credential Breaches

Credential stuffing is the most common consequence of data breaches: attackers take leaked username-password pairs and try them on thousands of other sites automatically. If every site you use has a unique password, a breach elsewhere costs you almost nothing — you change one password and move on.

Practical steps when you learn a service you use was breached:

  • Check your exposure on Have I Been Pwned or your password manager's breach alerts.
  • Change the breached password immediately, and anywhere you reused it.
  • Enable MFA on the affected account if it wasn't already on.
  • Review account activity for signs of use: unfamiliar sessions, password-reset emails, changed recovery details.
  • Expect phishing follow-ups. Breached contact data often feeds targeted phishing for months afterward.

Building a Password Policy for Teams

A modern policy is short, human-friendly, and enforced by technology rather than nagging:

  • Require length, not complexity: a 14+ character minimum or passphrases, with no composition rules.
  • Block known-bad passwords: screen new passwords against common lists and breach corpora.
  • No forced rotation. Change passwords only when there is evidence of compromise.
  • Require MFA everywhere, with security keys for administrators.
  • Provide and require a password manager, and encourage passkeys wherever offered.
Reconsider legacy rules: If your policy still forces quarterly changes and complex symbols, retiring those rules is one of the fastest improvements you can make — employees will thank you, and security will not suffer for it.

Summary

Modern password security rests on three pillars: long, unpredictable passphrases (or random passwords from a manager), uniqueness everywhere, and MFA on every important account. Passkeys are steadily removing the need for passwords altogether. When breaches happen, unique passwords plus MFA keep the damage to one account.

Conclusion

“Use strong passwords” was never enough advice, and the details of what counts as strong have genuinely changed. The modern playbook is simple to state: adopt a password manager, switch to long passphrases, enable MFA everywhere it exists, and accept passkeys whenever they are offered. That combination protects you against the vast majority of credential-based attacks without demanding heroic willpower.

Take the Next Step

Check whether your website exposes weak or reused credential risk, then secure your accounts with confidence.

Scan your website free →

Related Articles

Advertisement