Loading articles…
Security3 min read
How password managers, passkeys and the right kind of 2FA protect you — plus a 30-minute plan to lock down your email, bank and work accounts.
Full-stack engineer, New Delhi
Almost every account takeover I've helped clean up — a founder's email, a client's Instagram, a WordPress admin — came down to the same thing: a reused password that leaked from some other site. Attackers don't guess passwords any more; they take lists of billions of leaked email-and-password pairs and try them everywhere. This is called credential stuffing, and it works because people reuse passwords.
Here's how to make yourself a terrible target.
A password manager generates and remembers a long, random, unique password for every site. You remember one strong master password; it remembers the rest.
Good options:
| Manager | Notes |
|---|---|
| Bitwarden | Open source, generous free plan, works everywhere |
| 1Password | Polished, great for families and teams |
| Proton Pass | Privacy-focused, from the makers of Proton Mail |
| Built-in (Apple / Google) | Fine if you live in one ecosystem |
Your master password should be a long passphrase — four or five random words — that you use nowhere else. Turn on 2FA for the manager itself.
Then work through your accounts over a week, replacing old passwords with generated ones. Start with the ones that matter most (below).
Passkeys replace passwords entirely. Instead of a secret you type, your device holds a cryptographic key, unlocked with your fingerprint, face or PIN. They're:
Google, Apple, Microsoft, GitHub, Amazon, PayPal and many Indian apps now support them. Look for "Passkeys" in the account's security settings. Your password manager or phone can store and sync them across devices.
Where passkeys aren't available, add a second factor. Not all 2FA is equal:
| Method | Strength | Notes |
|---|---|---|
| Security key / passkey | Strongest | Phishing-resistant |
| Authenticator app (TOTP) | Strong | Google Authenticator, Aegis, 2FAS, or your password manager |
| Push approval | Good | Watch out for "MFA fatigue" spam prompts |
| SMS / email code | Weakest | Vulnerable to SIM-swap; still far better than nothing |
Save your backup codes when you enable 2FA — in your password manager or printed and kept somewhere safe. Losing your phone shouldn't lock you out forever.
Do these first; they protect everything else:
Enter your email at haveibeenpwned.com. Any account listed there? Change that password, and every account where you reused it.
Passkeys handle most phishing automatically, but stay alert to:
paypaI.com, hdfcbank-secure.inIf you run a business, enforce 2FA for everyone on shared tools, use a team password manager instead of spreadsheets or WhatsApp messages, and remove access the day someone leaves. One shared password in a group chat undoes all of the above.
Thirty minutes today saves you from the worst week of your year. Start with your email.
Security
A production security checklist for Next.js and Node.js: secrets, security headers and CSP, auth, server actions, validation and rate limiting.
Security
Broken access control, injection, XSS, CSRF, SSRF, leaked secrets and more — how each attack works and how to fix it, with code examples.
Security
A plain-English, 20-point security checklist for small business websites: HTTPS, updates, backups, logins, headers and what to do if hacked.