Passwords
Strong passwords still matter, but the way we handle them has changed since this post first ran in 2009. The default today is simple: let a password manager create a unique random password for every site, turn on two-factor authentication (2FA) wherever it is offered, and use a passkey when a service supports one. What actually makes a password strong Attackers guess and crack passwords with dictionaries, leaked lists, and raw computing power. Strength comes from: ...