Passwords & Authentication Checklist
Intro¶
Most reported data breaches are caused by the use of weak, default, or stolen passwords. You should use long, strong, and unique passwords, manage them in a secure password manager, enable 2-factor/Multi-factor authentication, keep on top of breaches, and take care while logging into your accounts.
Checklist¶
Critical and Essential Activities¶
-
Use Strong Passwords
Priority: Critical
If your password is too short, then it can be easily cracked through brute force or guessed by someone. Use a long, strong and unique password for each of your accounts – a Password Manager (see below) will help you create strong passwords. Length matters more than complexity – use 12+ characters, with Mix of uppercase and lowercase letters, at least one number, and at least one special character (-,#,!,&,%,*,~,§, etc.) (For example, "Marathon28-Harmful55-89Shorts", is an easy-to-read strong passphrase, "mypass" is not!) (DNC Jan 2026 and test your password at HowSecureIsMyPassword). -
Use a Secure Password Manager
Priority: Critical
Use a secure password manager to encrypt, store, and fill your authentication credentials, such as BitWarden, 1Password, or KeePass / KeePassXC. It is impossible to remember hundreds of strong and unique passwords. A password manager generates, stores, and auto-fills your login credentials for you. All your passwords are encrypted against a master password (which you must remember, and it should be very strong). Most password managers have browser extensions and mobile apps, so your passwords can be auto-filled on any of your devices. (DNC Jan 2026) -
Don't Reuse Passwords
Priority: Essential
Use a different password for each of your online accounts (such as e-mail, social media, banks, and other login services). Use a Password Manager (see above) to keep track of all your passwords. If you reuse a password on one site and it is leaked, then a criminal could easily gain unauthorized access to other accounts. -
Avoid Sharing Passwords
Priority: Essential
While there may be times that you need to share access to an account with another person, you should generally avoid doing this because it makes it easier for the account to become compromised. If you absolutely do need to share a password — for example, when working on a team with a shared account — this can be done via features built into a password manager, or with a "temporary link" tool like Bitwarden Send or OneTimeSecret.com to safely send encrypted information. (see also E-mail Checklist) -
Enable Multi-Factor Authentication (2FA/MFA)
Priority: Critical
2FA or MFA (2 or Multi-Factor-Authentication) is where you must provide both something you know (a password) and something you have (such as a code on your phone) to log in. (MFA can also include “something you are”, like a fingerprint as biometric data.) This means that if someone has obtained your password (e.g.,through phishing, malware, or a data breach), they still cannot log into your account.
Download an authenticator app like Bitwarden Authenticator or Google Authenticator (for Android or iOS) onto your phone, and then go to your account security settings and follow the steps to enable 2FA (typically this includes scanning a QR code and confirming with a 6-digit code). When you next log in, you will be prompted for the 6-digit code that is displayed in the app on your phone. It works without an internet connection and the code usually changes every 30 seconds.
If possible, use an authenticator app rather than e-mail or SMS for 2FA/MFA (DNC Jan 2026 and see Reference Links below). -
Use a Device Passkey (usually Biometric)
Priority: Essential
Passkeys are a newer password replacement technology that typically use a device-based biometric (fingerprint or facial scan) verification to provide secure access. (DNC Jan 2026) Caution: in some jurisdictions authorities can require that you provide biometric identifiers, but they cannot require you to divulge a password (DNC Jan 2026) . -
Keep Backup Codes Safe
Priority: Essential
When you enable multi-factor authentication, you will usually be given several codes that you can use if your 2FA method is lost, broken, or unavailable. Keep these codes somewhere safe to prevent loss or unauthorized access. You should store these on paper or in a safe place on disk (e.g., in offline storage or an encrypted file/drive). Don't store these in your password manager as 2FA sources and passwords should be kept separately.
Recommended Activities¶
-
Sign Up for Breach Alerts
Priority: Recommended
After a website suffers a significant data breach, the leaked data often ends up on the internet. Firefox Monitor, Have I Been Pwned, and DeHashed allow you to sign up for monitoring, where they will notify you if your email address appears in any new data sets. It is useful to know as soon as possible when this happens so that you can change your password for the affected account. (see also E-mail Checklist for alias e-mail suggestions) -
Shield your Password/PIN
Priority: Recommended
When typing your password in public places, ensure you are not in direct line of sight of a CCTV camera and that no one can see over your shoulder. Cover your password or pin code while you type, and do not reveal any plain text passwords on your screen. -
Update Critical Passwords Periodically
Priority: Recommended
Update passwords for sensitive accounts annually. Database leaks and breaches are common, and likely several of your passwords are already somewhere online. Occasionally updating passwords of security-critical accounts can help mitigate this. Ensure that all your passwords are long, strong, and unique. -
Don't Save your Password in Browsers
Priority: Recommended
Most modern browsers offer to save your credentials when you log into a site. Don't allow this, as they are not always encrypted and could allow someone to gain access to your accounts. Instead, use a dedicated password manager to store (and auto-fill) your passwords. -
Avoid Logging In on Someone Else's Device
Priority: Recommended
Avoid logging in on other people's computers since you can't be sure their system is clean. Be especially cautious of public machines, as malware and tracking are more common here. When using someone else's machine, ensure that you're in a private/incognito session (Use Ctrl+Shift+N / Cmd+Shift+N / Ctrl+Shift+P -on Firefox). This will prevent the browser from saving your credentials, cookies, and browsing history. -
Never Answer Online Security Questions Truthfully
Priority: Recommended
If a site asks security questions (such as place of birth, mother's maiden name, or first car, etc.), don't provide real answers. It is a trivial task for hackers to find out this information online or through social engineering. Instead, create a fictitious answer, and store it inside your password manager. -
Don't Use a 4-digit PIN
Priority: Recommended
Don't use a short PIN to access your smartphone or computer. Instead, use a text password or a much longer PIN. Numeric passphrases are easy to crack (a 4-digit PIN has 10,000 combinations, compared to 7.4 million for a 4-character alpha-numeric code). -
Avoid Using SMS for MFA
Priority: Recommended
When enabling multi-factor authentication, opt for app-based codes or a hardware token if supported. SMS is susceptible to several common threats, such as SIM-swapping and interception. If a website or service requires an SMS number for recovery, consider purchasing a second pre-paid phone number used only for account recovery (DNC Jan 2026) .
Advanced Activities¶
- Consider Unique Usernames
Priority: Advanced
Having different passwords for each account is a good first step, but if you also use a unique username, email, or phone number to log in, then it will be significantly harder for anyone trying to gain unauthorised access. The easiest method for multiple emails is using auto-generated aliases for anonymous mail forwarding. This is where [anything]@yourdomain.com will arrive in your inbox, allowing you to use a different email for each account (see Mail Alias Providers). Usernames are easier since you can use your password manager to generate, store, and auto-fill these. Virtual phone numbers can be generated through your VOIP provider.
References and Software Links¶
- DNC Security Checklist
- HowSecureIsMyPassword
- How to Create Strong Passwords -NCA
- What is a Password Manager -NCA
- What is Multifactor Authentication (MFA) -NCA
- Use Two-Factor Authentication -FTC
- Set up Bitwarden Password Manager
- Google Authenticator for your Gmail Account -YouTube
- Bitwarden Authenticator -standalone