Guide
Ten common password mistakes, and how to fix them
Most account takeovers start with an ordinary password habit. Here are the ten we see most, with a simple fix for each.
1. Reusing passwords
When one website leaks, attackers try the same email and password everywhere else. Use a different password for every account; a password manager remembers them.
2. Short or predictable passwords
Names, dates, keyboard patterns and words with a number on the end are the first things attackers try. Long and random wins.
3. Seasonal updates
Changing Summer2026! to Autumn2026! is easy to guess. Change passwords when there is a reason, and make the new one unrelated.
4. Spreadsheets and sticky notes
Shared documents get copied, forwarded and left in old folders. Keep passwords in an encrypted vault instead.
5. Sharing passwords in chats and email
Messages are kept for years and searched easily. Share through a password manager, or with a link that expires.
6. Skipping two-step login
A second step stops most attacks that start with a stolen password. Turn it on wherever it is offered.
7. True answers to security questions
Your first school is often findable online. Treat answers as extra passwords and store them in your vault.
8. Ignoring breach warnings
If a service you use is breached, change that password and any account that shared it.
9. Signing in through links in messages
Phishing pages look like the real thing. Open the site yourself, and let a password manager fill in only where the address matches.
10. A weak master password
Your password manager's master password protects everything else. Make it a long passphrase you will remember, and never reuse it.
Our free password strength checker and breached password checker run in your browser and send nothing that could reveal your password.
Fix them all at once
KeyCare Pass generates, remembers and fills strong passwords for you.