Long, unique, memorized
If you use a password manager, your master password is the single key to everything else. NIST's current guidance (SP 800-63B) favors long passphrases (16+ characters) over short complex passwords. A sentence you can remember is stronger than a random 8-character string you cannot.
The master password must be unique (not reused anywhere else) and memorized. Consider writing it on paper stored in a secure physical location (safe, locked drawer) as a backup. Never store it in a digital file.
One strong password replaces a hundred weak ones
The average person has over 100 online accounts. Without a password manager, people reuse passwords across sites. One breach exposes every account using that password.
A password manager generates unique, random passwords for every account and stores them encrypted behind your master password. You only need to remember one strong password instead of a hundred weak ones.
What happens if you cannot access your manager
Consider sharing access instructions (not the password itself) with a trusted person via a sealed envelope in a safe deposit box or a secure document vault. Some password managers offer emergency access features that grant a designated contact access after a waiting period.
- Master password: 16+ characters, unique, memorized
- Passphrases beat complex short passwords (NIST SP 800-63B)
- Write the master password on paper in a secure physical location
- Password manager = one strong password instead of 100 weak ones
- Plan for emergency access by a trusted person
- NIST SP 800-63B — NIST digital identity and password guidelines.