Password managers, passphrases, and why 2FA matters more than complexity.
Rahul got his work laptop on a Monday. By Friday he had accounts for email, the HR portal, the file server, payroll and two chat tools — and he did what almost everyone does: used the same password for all of them.
This lesson is about why that one habit is exactly what attackers are counting on, and the two upgrades that fix it in a single lunch break.
How passwords actually get stolen
Nobody sits at your login screen typing guesses. Here is what really happens:
A website you joined years ago — a forum, a shop, a game — gets hacked, and its whole list of emails and passwords leaks onto the internet.
Criminals feed that list into software that tries every email-and-password pair on hundreds of other sites: email providers, banks, shops, work systems.
Wherever you reused that password, they are in.
This is called credential stuffing, and it means reuse is the real danger. A brilliant password used in ten places is weaker than an average password used in one, because you are only ever as safe as the sloppiest website you gave it to.
🔒
Keep reading with Pro
You are reading the free preview. Module 1 of every course is free forever — Pro unlocks the rest of this lesson, every other module of every course, removes ads, and adds workbooks and certificates.