What Makes a Password Secure in 2026?
Learn the latest best practices for creating and managing secure passwords in today's threat landscape.
Articles, guides, and best practices for keeping your accounts secure.
Learn the latest best practices for creating and managing secure passwords in today's threat landscape.
Length beats clever complexity. Use 16–20 characters for everyday accounts, 20–24 for high-value logins, and 5–7 random words for memorized passphrases.
What TOTP is, how 6-digit codes are calculated, how to use passwords.lu’s local generator, and five detailed real-world use cases.
A good password manager already generates passwords. When a standalone generator still helps—and when the manager is enough.
WWDC 2026 previewed an Apple Intelligence agent that can rotate weak and compromised passwords. Why friction kills hygiene — and what to do until iOS 27 ships.
Meta confirmed 20,000+ Instagram takeovers via an AI recovery bug. Why password resets without 2FA fail, and what to do now.
ChatGPT passwords look random—but LLMs predict patterns, not cryptographic entropy. Why CSPRNG generators are safer.
Generate passwords, passphrases, PINs, API keys, usernames, and guest Wi‑Fi QR codes in Chrome — local, private, with optional HIBP breach checks.
Generate passwords, passphrases, PINs, API keys, and usernames in your editor — with local strength checks and optional HIBP breach lookups.
Stolen credentials drive 39% of breach chains. Email, banking, managers, and dev accounts need MFA, passkeys, or hardware keys—not passwords alone.
A practical decision guide for sharing passwords, recovery codes, and other secrets without leaving unnecessary traces behind.
How browser password generators use Web Crypto randomness, what entropy means, and why rejection sampling avoids modulo bias.
A high-level introduction to Password-Authenticated Public-Key Encryption and how Half-Ideal Ciphers make practical post-quantum PAPKE variants possible.
Usernames are not secrets, but they are identifiers. A deeper look at reuse, breadcrumbs, random vs memorable handles, email aliases, and realistic limits—with links to both generator modes.
Keep your personal devices isolated while still giving visitors fast internet. Learn why guest SSIDs matter and how to set them up safely.
Understanding the techniques hackers use to break into accounts and the simple steps you can take to protect yourself.
Even one reused password can cascade into account takeovers. See why low-risk sites are not low-risk and how to fix reuse for good.
Step-by-step guide to checking if your passwords have been exposed in data breaches and what to do about it.
A detailed guide to Diceware: where it comes from, why it works, how many words you need, and how to generate a passphrase manually with dice or digitally with local wordlists.
What passkeys are, real registration and sign-in flows, common misconceptions, and why adoption has lagged the hype—while passwords and passkeys still coexist.