Skip to main content
U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Passwords and Accounts: Best Cybersecurity Practices

A majority of account take-overs start with weak or compromised passwords. The Secret Service recommends following these protective measures when creating passwords to take control of your digital accounts and protect yourself from malicious actors.

•   Step 1 - Get a password manager. A password manager is a secure encrypted electronic vault, designed to store and organize your passwords across all your devices. It comes with a password generator tool, to help you create strong and randomized passwords.  A password manager simplifies your login experience by securely logging into your accounts for you.
•    Step 2 - Secure your password manager with a strong password and multiple factor authentication in form of biometrics and passkeys replacing traditional passwords with cryptographic keys stored on your devices.
•    Step 3 – Register all your accounts into your password manager. Use the password generator to create strong and unique passwords for all your accounts. 
•    Step 4 – Turn on Multifactor Authentication on all your accounts. Leverage Passkeys whenever possible as they are phishing resistant and extremely secure. 

Other best practices:

•   Use phishing-resistant authentications, like FIDO passkeys, or hardware-based security tokens.  Wherever possible, disable SMS, email, or phone one-time passwords (and similar authentication or account recovery options) to ensure effective protection using multifactor authentication.  
•    Change passwords regularly and use different passwords for each system and account.
•    Immediately change factory preset passwords on devices, to include Wi-Fi routers and smart devices.
•    Use answers only you know, for security questions.
 

Weak Passwords

Strong Passwords

fb123456

Bu0#L9/cij8X,#m>uzf

John0623

mjW7bY;dK31X?vP/fKy8Ls

Qwerty123

X5csU*m@4dPg<Wd5?l9”bR

TurtlePower0510

BE7:>25/!+uD.:KA-k~Gb<8]

Bu0#L

iU!dn0<$.?F”5Zkb![mt(=S]

 

•   Too Short
•   Contains Dictionary Words
•   Has Sequential Numbers


 

 

•    Upper and lowercase letters
•    At least 20-50 characters
•    Symbols
•    Varied, non-sequential numbers
•    No personal data, like your birthday
•    No Dictionary Words

 

Examples of password managers include but are not limited to:

•   1Password
•    Aura
•    Bitdefender PM
•    Bitwarden
•    Dashlane
•    EnPass Password Manager
•   iCloud Keychain
•    Keeper
•    LastPass
•    LogMeOnce
•    Nordpass
•    Norton
•    Proton Pass
•    RoboForm
•    Samsung Pass
•    Samsung Wallet

Example of Password Manager

PW Manager

Visit the Cyber Hygiene and the Avoid Scams webpages for more information on cybercrime prevention.