How to Actually Stop Reusing Passwords

Using the same password everywhere means one website's leak unlocks all of your accounts. The realistic fix is to give unique passwords to the five accounts that actually matter, starting with your email, rather than trying to change all 200 in one weekend.

Here's the part most people don't know: you don't get hacked because someone targeted you. Some website you signed up for in 2014 gets breached, your email and password end up on a list, and criminals run software that tries that exact combination on every major site on the internet. That's called credential stuffing, where a stolen password from one site gets tried automatically in the login box of a thousand others. If the password is the same everywhere, they're in everywhere, and somebody else's security failure becomes yours.

Why "change everything" fails

Everyone who's told to stop reusing passwords hears the same advice, which is to set a unique password for every account starting now. Faced with 200 accounts, most people end up changing none of them, so the realistic plan is to fix five, which takes about a Saturday morning.

The five accounts to fix first

  • 1. Your email. This one comes first and it isn't optional, because every other account sends its password reset link to your email, and whoever controls it controls everything downstream. Give it a long password used absolutely nowhere else.
  • 2. Your bank, along with anything else that moves money, such as PayPal, Venmo, or your retirement account.
  • 3. Anywhere your credit card is saved. Amazon is the most common example, and a hijacker doesn't need your bank if your card is one click away.
  • 4. Your main social account. This matters not because of your posts, but because a stolen account gets used to scam your friends. We wrote up what recovery looks like when it's too late, and it's a bad afternoon.
  • 5. The one that keeps making you reset. Most people have an account whose "forgot password" page they see every month. Next time you're there, give it a real, unique password so the cycle ends.

How to make five passwords you won't hate

Length matters more than cleverness. Four unrelated words ("bison kettle sideways plum") is easier to type and harder to crack than "P@ssw0rd7!". Two rules apply:

  • Avoid variations on a theme, because "Hockey2024!" and "Hockey2025!" count as the same password, and cracking software is built to catch exactly that pattern.
  • You only need to memorize one of them, your email password. The rest can be stored or written down, which brings us to the next question.

Where do the passwords live?

Anywhere is better than in your head as one reused password. In rough order:

  • A password manager (app or hardware) stores hundreds of unique passwords so you don't have to remember them.
  • Your browser's "save password" offer is fine for low-stakes accounts, though it ties everything to that browser account.
  • A paper notebook at home gets dismissed more than it deserves, because credential-stuffing software cannot read paper in your kitchen drawer. Just don't stick it to a monitor or carry it around.

After the five

Change the rest as life brings you to them. If you're logging into an old account anyway, give it a unique password while you're there, and if you hear that a site you use was breached, fix that one right away. If a password you still reuse shows up in a breach today, go straight to what to do when a password is compromised.

Quick answers

Is it bad to use the same password everywhere?

Yes, because one breach at one website unlocks every account that shares the password, since criminals automatically try leaked passwords on other sites. It's the single riskiest password habit there is.

How many passwords should I have?

One per account, but you only need to memorize about one, your email password. Everything else can live in a manager, a device, or a notebook at home.

Do I have to fix all my accounts at once?

No, and trying to is why most people quit. Fix email, bank, saved-card sites, your main social account, and the one you keep resetting, which covers most of the real risk, and do the rest gradually.

Full disclosure on why we care: we're NuLenke, and we make Lomenett, a password typer. It's a small offline USB stick that holds up to 1,000 logins and types them for you, which makes a different password for everything possible without memorizing anything, and it's launching soon. This plan works with a notebook too, and helping a less techy family member start theirs is covered in Passwords for Parents.