Lesson 6 / 24

Strong, Unique Passwords

Generate long random passwords or passphrases and never reuse them.

Length and uniqueness win

A long random password is hard to guess, but reuse is the bigger danger: when one site is breached, attackers try the same email and password on other sites ("credential stuffing"). Let the manager generate a different password for every account.

Generating one from the CLI

The 1Password CLI can generate a password with a chosen length. Memorable passphrases of several random words are good for the one password you must type, such as your master password.

op item create --category=login --title="Example" \
  --generate-password=24,letters,digits,symbols

Check for breaches

Use Watchtower in 1Password to flag reused, weak or breached passwords, and fix the oldest and most important accounts first, such as email, banking and cloud consoles.

Quick check: Why is reusing a password across sites dangerous?

  • Sites slow down
  • A breach on one site exposes your other accounts
  • Browsers forbid it
  • It uses more storage
Answer

A breach on one site exposes your other accounts — Attackers replay leaked credentials on other services, so every account needs its own password.