Household Records, Digital Life and Communications · Chapter 3

Passwords, authentication and account recovery

Protect the accounts that control household money, identity, communications, files, and recovery.

Start here

Not all accounts carry the same risk

The household's digital accounts range from streaming services to bank logins. They do not all need the same level of attention. Prioritize security effort on the accounts that control money, identity, communications, files, and the ability to recover other accounts.

Primary email deserves special attention. The FTC specifically notes that a compromised email account can allow an attacker to request password-reset links for other services. If one account gets the strongest protection the household can manage, it should be the email account that receives reset links for everything else.

High-priority accounts

Primary email

Password manager

Bank and credit union

Payment apps

Credit card accounts

Tax filing accounts

Government accounts

Cellular carrier account

Cloud storage

Shopping accounts with saved payment

Social media

Work and school portals

For the full technical guide to account security, including step-by-step setup, see Locking Down the Accounts That Matter Most.

Current guidance

What actually makes a password strong

NIST published SP 800-63B-4 in 2025, updating federal digital identity guidelines. Several widely taught password habits are no longer considered best practice by NIST.

Make it long

NIST now requires a minimum of 15 characters for passwords used as a single factor in covered federal systems. Consumer websites vary, but the direction is clear: length is the primary strength factor. A passphrase of several ordinary words is typically stronger and easier to remember than a short password with forced symbol substitutions.

Make it unique

NIST explains that reusing a password across services enables password-stuffing attacks, where a credential stolen from one breach is tried against other accounts. Each important account should have its own password.

Use a password manager

Both NIST and CISA support password manager use. NIST requires conforming systems to allow password managers and notes they increase the likelihood of stronger passwords. CISA recommends them as a practical way to create and store unique passwords. A password manager makes unique credentials manageable instead of impossible.

Stop forced periodic changes

NIST states that verifiers should not require arbitrary periodic password changes. Change a password when it is compromised, when reuse is discovered, when suspicious activity appears, or when the user chooses to. Forced changes every 90 days without cause are no longer recommended.

Composition rules have shifted

NIST now emphasizes length and rejecting known-compromised passwords over arbitrary mixtures of uppercase, lowercase, numbers, and symbols. A specific website may still enforce its own composition requirements, but the core modern principle is length, uniqueness, and avoiding predictable patterns like P@ssw0rd.

NIST SP 800-63B-4 is written for digital identity systems, not as a direct household password law. The principles translate well to consumer use, but individual websites set their own requirements.

Beyond the password

Multifactor authentication and phishing resistance

The FTC recommends two-factor authentication because a stolen password alone may not be sufficient to enter the account. CISA identifies MFA as one of its core consumer security practices. The household rule is simple: enable MFA on every important account that supports it.

Not all MFA methods provide the same level of protection. NIST distinguishes between methods by their resistance to phishing.

Method Phishing resistant (NIST definition) Notes
Password alone No Can be entered on a fake site
SMS or email code No Still substantially better than password only
Authenticator app code No Manually entered, so phishable, but useful protection
Passkeys and security keys Can be, when properly implemented Cryptographic, not manually entered

The practical hierarchy: use MFA. When a service offers a stronger phishing-resistant option such as a properly implemented passkey or security key, consider using it for important accounts. Do not skip available MFA merely because a stronger method is not offered. SMS codes are substantially better than no second factor.

Passkey and security key adoption is evolving rapidly. The Account Security guide covers the current landscape in more technical depth.

Before you need it

Account recovery is part of account setup

A secure account that cannot be recovered after a lost phone is not a complete household system. For every high-priority account, the household should be able to answer: if the phone is lost tonight, how do we regain access tomorrow?

Recovery email

Verify that the recovery email address is current and accessible. A recovery email tied to an old account you cannot reach defeats the purpose.

Recovery phone

Confirm the recovery phone number still belongs to the household. A number from a previous phone plan or a former household member creates a lockout risk.

Recovery codes

Store recovery codes or backup authenticators somewhere that remains accessible if the primary phone is lost. A recovery code saved only on the phone it is supposed to recover is useless when that phone is gone.

Active sessions

Periodically review which devices are logged into important accounts. Remove sessions from old devices, former household members' devices, or anything unrecognized.

NIST's current guidance recognizes account-recovery mechanisms and recovery codes as part of authenticator lifecycle management. Setting up recovery before it is needed is not optional extra work. It is part of properly securing the account.

Next

Secure the devices and the network

Strong account credentials protect what is behind the login. The next step is protecting the devices and network that carry those credentials: keeping software updated, locking devices, securing the home router, and recognizing when a message is trying to bypass all of it.

Chapter 4: Device Security, Home Network and Recognizing Fraud