Password Security Blog

Articles, guides, and best practices for keeping your accounts secure.

All Articles

Data Breaches•September 10, 2026

My Password Was Found in a Data Breach. What Should I Do?

Finding a password in breach data does not mean someone is in your account. It means that password should no longer be trusted—here is the sequence to follow.

8 min readRead More
Authentication Threats•September 9, 2026

Password Spraying Surged 155x — Because MFA Never Fired

Huntress saw spraying jump 155x in H1 2026. Attackers reused leaked passwords through Azure CLI’s legacy ROPC flow, skipping MFA that looked enabled.

7 min readRead More
Privacy & Identity•September 10, 2026

Creating a Safer Username: What Should It Reveal?

A username is a public label, not a password. What it should reveal, what to leave out, and how to create a random username in your browser.

5 min readRead More
Authentication Threats•September 8, 2026

Why Traditional MFA Still Loses to Adversary-in-the-Middle Attacks

Traditional MFA stops stuffing, but AitM phishing can still steal passwords, codes, and session cookies in real time. Why FIDO2 and passkeys resist that attack.

6 min readRead More
Passwordless Authentication•September 8, 2026

Sync Fabric Is Not a Passkey-Only Risk

Synced passkeys share cloud trust with password managers, email OTP, and synced TOTP. How to harden the fabric instead of treating passkeys as a special failure.

6 min readRead More
Account Recovery•September 8, 2026

Device Loss: Synced Passkeys vs Romanticized MFA

What happens if you lose your phone? How synced passkeys, single-device FIDO credentials, and real-world MFA compare on availability.

6 min readRead More
Passwordless Authentication•September 8, 2026

How to Keep Passkeys Strong: A Practical Checklist

Device hygiene, sync fabric protection, backups, and what sites must implement so passkey benefits are not undermined.

6 min readRead More
Passwordless Authentication•September 8, 2026

Are Passkeys Really Multi-Factor Authentication?

Same-device does not mean single-factor. How user verification makes passkeys MFA—and why the critique also applies to SMS MFA.

5 min readRead More
Security Basics•July 29, 2026

How Long Should a Password Be in 2026?

Length beats clever complexity. Use 16–20 characters for everyday accounts, 20–24 for high-value logins, and 5–7 random words for memorized passphrases.

8 min readRead More
Two-Factor Authentication•July 29, 2026

What Is TOTP? How Authenticator Codes Work — and How to Use Our Generator

What TOTP is, how 6-digit codes are calculated, how to use passwords.lu’s local generator, and five detailed real-world use cases.

12 min readRead More
Password Management•July 27, 2026

Password Generator vs Password Manager: What You Actually Need

A good password manager already generates passwords. When a standalone generator still helps—and when the manager is enough.

7 min readRead More
Password Management•July 22, 2026

Apple’s Passwords App May Finally Fix the Hard Part: Changing Bad Passwords

WWDC 2026 previewed an Apple Intelligence agent that can rotate weak and compromised passwords. Why friction kills hygiene — and what to do until iOS 27 ships.

6 min readRead More
Security Threats•July 20, 2026

Instagram’s AI Password Reset Was the Weak Link — 2FA Wasn’t

Meta confirmed 20,000+ Instagram takeovers via an AI recovery bug. Why password resets without 2FA fail, and what to do now.

4 min readRead More
Password Engineering•July 20, 2026

Why You Shouldn’t Use AI to Generate Passwords (And What to Use Instead)

ChatGPT passwords look random—but LLMs predict patterns, not cryptographic entropy. Why CSPRNG generators are safer.

8 min readRead More
Product•July 17, 2026

Passwords for Chrome Is Live

Generate passwords, passphrases, PINs, API keys, usernames, and guest Wi‑Fi QR codes in Chrome — local, private, with optional HIBP breach checks.

4 min readRead More
Product•July 4, 2026

Passwords for VS Code Is Live

Generate passwords, passphrases, PINs, API keys, and usernames in your editor — with local strength checks and optional HIBP breach lookups.

4 min readRead More
Account Security•July 3, 2026

10 Accounts You Should Never Protect with Just a Password

Stolen credentials drive 39% of breach chains. Email, banking, managers, and dev accounts need MFA, passkeys, or hardware keys—not passwords alone.

9 min readRead More
Secure Sharing•May 4, 2026

Should You Send This by Email, Chat, a Secure Note, or a Password Manager?

A practical decision guide for sharing passwords, recovery codes, and other secrets without leaving unnecessary traces behind.

5 min readRead More
Password Engineering•May 12, 2026

Where Password Randomness Comes From

How browser password generators use Web Crypto randomness, what entropy means, and why rejection sampling avoids modulo bias.

6 min readRead More
Cryptography•May 13, 2026

HIC Is All You Need: Post-Quantum PAPKE Explained

A high-level introduction to Password-Authenticated Public-Key Encryption and how Half-Ideal Ciphers make practical post-quantum PAPKE variants possible.

8 min readRead More
Privacy & Identity•May 10, 2026

Why Your Username Still Matters (and How to Choose One Wisely)

Usernames are not secrets, but they are identifiers. A deeper look at reuse, breadcrumbs, random vs memorable handles, email aliases, and realistic limits—with links to both generator modes.

6 min readRead More
Home Network Security•March 20, 2025

Why Every Home Needs a Guest Wi-Fi Network

Keep your personal devices isolated while still giving visitors fast internet. Learn why guest SSIDs matter and how to set them up safely.

3 min readRead More
Security Threats•March 5, 2025

How Hackers Crack Your Passwords (and How to Stop Them)

Understanding the techniques hackers use to break into accounts and the simple steps you can take to protect yourself.

3 min readRead More
Password Management•February 27, 2025

Password Reuse: Why Even One Repeat Can Compromise Everything

Even one reused password can cascade into account takeovers. See why low-risk sites are not low-risk and how to fix reuse for good.

3 min readRead More
Data Breaches•February 10, 2025

How to Check If Your Password Has Been Leaked

What breach checks can tell you, what they cannot, and what to change after exposure.

5 min readRead More
Password Techniques•April 28, 2026

Diceware Explained: Origins, Security, and How to Roll Your Own Passphrase

A detailed guide to Diceware: where it comes from, why it works, how many words you need, and how to generate a passphrase manually with dice or digitally with local wordlists.

4 min readRead More
Passwordless Authentication•February 27, 2025

Passkeys: The Next Frontier in Passwordless Authentication

What passkeys are, real registration and sign-in flows, common misconceptions, and why adoption has lagged the hype—while passwords and passkeys still coexist.

10 min readRead More

Stay in the loop

Get occasional updates on new tools, security tips, and improvements — no spam, no noise, unsubscribe anytime.