Nano-lesson · usually takes 2–3 minutes
Strong passwords & two-factor
Long passphrases, a password manager and MFA — the short version.
Do you reuse your password?
Do you use the same password at work as on a webshop? When the webshop gets breached — and it will — criminals automatically try that same password everywhere else. That's why reuse is one of the most common ways in.
Do
- Use long passwords (a passphrase of 4+ words is better than "Summer2024!").
- Never reuse the same password across multiple services.
- Use a password manager — an app that remembers and fills in your passwords for you. Your phone already has one built in (iPhone: the "Passwords" app · Android: Google).
- Turn on two-factor (MFAMulti-factor authentication (MFA/2FA): an extra step beyond your password — such as a code or a tap on your phone — so a thief can't log in with the password alone.) everywhere you can.
Where is it safe to type your password?
https://login.my-company.co.uk
Only on the genuine site with https and a padlock — and let your password manager fill it in. It will refuse to autofill on a fake domain, so a missing autofill is a red flag.
If you get an unexpected MFA prompt
don't approve it — it can mean someone is trying to log in with your password.
Remember
What the research says
Two-factor (MFA) reduces the risk of account takeover by roughly 99.2% — even after a password leak. However, a password manager only helps if you let it generate new, unique passwords for you; and only around 13% change a leaked password within three months, so reuse is the big culprit.
Microsoft Research 2023 · Lyastani et al., USENIX Security 2018 · Bhagavatula et al., CMU 2020.
Question 1 of 3
Which password is hardest to crack?
✓ Correct!
Length beats symbols: four random words take infinitely longer to guess than six characters — and patterns like "Summer + year" are the first thing machines try.
Question 2 of 3
You use the same password for work and a webshop. The webshop gets hacked. What does that mean for your work account?
✓ Correct!
Criminals test leaked passwords against thousands of other services completely automatically — and your email address is usually the username. Change it, and never reuse passwords.
Question 3 of 3
You need to create a login for a new system. How do you choose a password?
✓ Correct!
A "strong" password doesn't help if it leaks in one place and is used everywhere — and machines guess "+1 at the end" instantly. Unique every time; let the manager remember it.
Well done!
You've completed one of the foundation courses — the ones everyone gets for free.
With a free login:
- Your points, progress and course certificate are saved.
- You get courses tailored to your role — not just the foundation courses.
- We send training exactly when you need it — for example, as a follow-up to a phishing test.