Security & Scams
5 min readBy ARK Computer Repair technicians

Passwords: the simple system that actually works

Most accounts aren't broken into by guessing. They're opened with a password that was already stolen from somewhere else entirely — a shop, a forum, an old service that leaked years ago.

So the advice that matters isn't "make it complicated". It's "never use the same one twice".

Why reuse is the whole problem

When a company is breached, the stolen email-and-password pairs are sold in bulk. Automated tools then try those pairs on hundreds of other sites — email, shopping, banking. If you reused the password, they're in, and no amount of capital letters or exclamation marks helps.

You can check whether your own address has appeared in a known breach at haveibeenpwned.com. Most people are on at least one list, which is normal — it only matters if the password is still in use somewhere.

What a good password looks like now

The old rules produced passwords that were hard for people to remember and easy for computers to guess. Length beats complexity.

  • Three or four unrelated words strung together, for example purple-harbour-kettle-92
  • At least 14 characters where the site allows it
  • Nothing drawn from your life: no names, pets, birthdays, street or football team
  • No pattern you repeat across sites, like the site name plus your usual password
  • Change a password when there's a reason to — not on a routine every 90 days

The three passwords worth memorising

You only need to hold a few in your head. Make these three long, unique and unwritten:

  • Your email password — it's the master key, because every other account resets through it
  • Your password manager's master password
  • Your computer or phone unlock code

How a password manager actually works

It's an encrypted vault. You remember one strong password; it remembers everything else, generates new ones and fills them in for you. Bitwarden and 1Password are both sound choices, and the ones built into Apple, Google and Microsoft accounts are fine too if you live inside one of those.

The common worry — "isn't it dangerous to keep them all in one place?" — is understandable but backwards. The realistic risk isn't the vault being cracked; it's you reusing one password across 40 sites because remembering 40 is impossible.

If you'd rather use paper

A notebook is far better than reusing one password everywhere. Burglars are not after your passwords; automated credential stuffing is. Keep the book somewhere sensible, don't write the website next to each one in obvious terms, and never keep it in a file called passwords on the computer itself.

More from the advice centre