Password Security Learning Hub
Key Takeaways
- Length beats complexity. A 20-character password is exponentially stronger than a complex 8-character one.
- Aim for 80+ bits of entropy for personal accounts and 128+ bits for cryptographic secrets.
- Never reuse passwords. One breach should never compromise a second account.
- Use a password manager + MFA. Prefer passkeys or hardware keys over SMS OTP.
- Rotate only on compromise. Forced periodic rotation degrades password quality (NIST SP 800-63B).
Definition · How It Works · Examples
Entropy
Entropy is the log₂ of the number of possible passwords a generator could produce. A 20-char password from a 94-symbol pool has log₂(94²⁰) ≈ 131 bits. Each added bit doubles the search space.
Hashing
Servers should never store plain passwords. They store a one-way hash (Argon2id, bcrypt, scrypt). Even if the database is leaked, the original password isn't directly recoverable.
Salting
A unique random salt is added before hashing each password. Salts prevent rainbow-table attacks and ensure that identical passwords produce different hashes.
MFA
Multi-factor authentication adds something you have (phone, hardware key) or are (biometric) to something you know (password). It defeats most credential-only attacks.
Passkeys
Passkeys are phishing-resistant credentials based on WebAuthn / FIDO2 public-key cryptography. No shared secret leaves your device — there's nothing for a server to leak.
Credential Stuffing
Attackers replay credentials leaked from one site against thousands of others. Unique passwords + MFA + breach monitoring stop this attack pattern entirely.
Best Practices Checklist
- Use 16+ characters for accounts, 32+ for vault master passwords.
- Use a passphrase for things you must memorize (vault master, disk encryption).
- Enable MFA on every account that supports it — prefer passkeys.
- Store all credentials in a reputable password manager.
- Never share passwords over chat or email — use a secure share feature.
- Audit your vault monthly for reused or weak passwords.
Common Mistakes
- Using personal info (birthdays, pet names, employer).
- Predictable substitutions (P@ssw0rd, Sup3r) — crackers know them.
- Reusing a "good" password across multiple sites.
- Writing passwords on sticky notes or unencrypted documents.
- Relying on SMS OTP as your only second factor.
Future of Authentication
WebAuthn
The browser-native API for FIDO2 credentials. Powers passkeys and security-key flows on every modern browser.
FIDO2
Open authentication standard combining WebAuthn + CTAP. Replaces passwords with public-key cryptography.
Hardware keys
YubiKey, Titan, Nitrokey — physical devices that sign challenges on-device. Resistant to phishing and remote attack.
Synced passkeys
Passkeys synchronized via your platform (iCloud Keychain, Google Password Manager, 1Password) for seamless cross-device login.