# Strong, Unique Passwords — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/pm-strong-passwords

> Generate long random passwords or passphrases and never reuse them.

## Length and uniqueness win

A long random password is hard to guess, but reuse is the bigger danger: when one site is breached, attackers try the same email and password on other sites ("credential stuffing"). Let the manager generate a different password for every account.

## Generating one from the CLI

The 1Password CLI can generate a password with a chosen length. Memorable passphrases of several random words are good for the one password you must type, such as your master password.

```bash
op item create --category=login --title="Example" \
  --generate-password=24,letters,digits,symbols
```

## Check for breaches

Use Watchtower in 1Password to flag reused, weak or breached passwords, and fix the oldest and most important accounts first, such as email, banking and cloud consoles.

**Quiz:** Why is reusing a password across sites dangerous?

- [ ] Sites slow down
- [x] A breach on one site exposes your other accounts
- [ ] Browsers forbid it
- [ ] It uses more storage

*Answer:* A breach on one site exposes your other accounts. Attackers replay leaked credentials on other services, so every account needs its own password.
