02Evidence C

Use a unique password solely for your email

If a password you use elsewhere gets stolen, attackers can use it to log straight into your email account. Once they gain access to your email, they can reset passwords for any other accounts linked to it. Therefore, your email password must be unique and never reused anywhere else.

Cost

No cost involved. Storing it in a password manager elimina…

Benefit

Credential stuffing is one of the easiest attack methods: attackers simply test stolen passwords against other…

Cost

No cost involved. Storing it in a password manager eliminates the need to memorize it. The real challenge lies in breaking the old habit of reusing one password across multiple sites.

Benefit

Credential stuffing is one of the easiest attack methods: attackers simply test stolen passwords against other accounts. If your email password is compromised, all accounts that rely on it for password recovery become vulnerable too. The US Cybersecurity and Infrastructure Security Agency recommends using a distinct, strong password of at least 16 characters for every account, and storing it via a password manager.

Original sources

US CISA. Use Strong Passwords. https://www.cisa.gov/secure-our-world/use-strong-passwords

Open source link
Book note

If you struggle to memorize passwords, use the built-in password manager in your web browser. It stores passwords for each site for you, which is far safer than reusing the same password everywhere. Avoid saving passwords in WeChat favorites or note-taking apps.

My note