Yes I am talking to YOU.

My full time job is to sit in front of a computer, so I spend a lot of time in and around the internet.
I’ve recently had some personal experience with the dark side of the internet and the people on it. That experience made me want to share some of the things I’ve learned about how to keep yourself safe in the digital era that we are all living in.
How many online accounts do you think you have?
Genuinely, if you counted every online account you’ve ever made for anything; every old social media, every site you bought some trinket from.
.
.
.
.
How many did you get? I bet you underestimated it. Just for a ballpark number, I have 579.
A password manager is a tool that you can use to store and easily access all of your passwords. It helps you generate random secure passwords (that you don’t have to remember!) so that you don’t have to keep using the same ones over and over.
Using a password manager also means that (for the most part), you can avoid typing out any of those passwords in the future. “But Chrome saves all my passwords!” Your browser will save your passwords if you let it. But what happens when you want to access one of those passwords on your phone? Or on someone else’s computer?
The good password managers all have browser extensions, apps for your phone, and websites. So no matter what computer or device you’re on, you will always have access to your passwords.
I’ve been preaching this whole “use a password manager” thing for years, and have talked to a number of people about what their current password strategy is. People typically use a few different passwords for every site they sign up for. Usually there are variations on those passwords by tacking a number or a few !s on the end. Maybe one “secure” password for their financial stuff.
When they need to sign into a site that they haven’t used in awhile, they just cycle through their passwords until their log in is successful! Occasionally they’ll fail to find the right variation, and use the “Forgot your password?” link to reset their password to the one they have been using most recently.
Unsurprisingly, this strategy is really, really insecure because of a hacking technique called “credential stuffing”.
Websites get hacked alllllllllll the time. A 2019 study found that on average there was an attempted hack on a website every 39 seconds. In 2026, AI is increasing that rate exponentially. While not all hack attempts are successful, plenty of them are.
Hackers take those stolen username/password combinations and “stuff” them into all the popular websites (e.g. banks, social media, online tools) and anyone who has reused their credentials now has two hacked accounts instead of one. Because some crappy little website that you signed up for one time got hacked, the hacker now has access to your bank info because you used the same login!
How can a password manager help with this?
Section titled: How can a password manager help with this?Password managers solve this problem by making every username/password combination that you use for every site completely unique. So if one site gets hacked and your credentials stolen, those credentials won’t get the hacker into any other site.
In addition to reusing passwords, many people tend to use very weak passwords. The weaker (i.e. shorter, simpler) a password is, the more easily it can be guessed by a computer. Computers often guess by starting with common passwords and trying variations. If that fails, they can just try every combination of letters and numbers. If your password is relatively short, it can be “brute forced” by a computer in seconds if there are no other constraints or delays.
Password managers solve this problem by generating long, complex, and random passwords that can’t be guessed or brute forced1.
But what if they hack the password manager!?
Section titled: But what if they hack the password manager!?When you sign into your password manager, you do so using a “master password”2. This becomes the only password you have to remember now. It should be long (more than 20 characters), complex, and completely unique from anything you’ve used online before.
Password managers work by encrypting your stored passwords using your master password. This means that even the password manager company themselves can’t access your stored passwords, because they don’t have your master password! So if someone hacks the password manager, all they get is a bunch of encrypted, meaningless text that is in no way helpful to them in accomplishing their nefarious tasks.
There are several to choose from:
- 1Password (The one I use)
- Apple’s Password Manager
- Proton Pass
- Bitwarden
- Dashlane
LastPass- I can no longer recommend LastPass after how many data breaches they’ve had
1Password is the best one when it comes to features and ease of use, but is also more expensive. Search for feature comparisons between them if you’d like to know more.
No matter which one you choose, you’ll be far better off than you were before using one.
The goal is to eventually have every password for every site you use be:
- In your password manager
- Changed to something long and random (instead of one of the 3 passwords that you rotate between)
But you don’t have to do it all at once! Start with your most important accounts first:
- Your bank
- All financial institutions, like your credit card
- Any bills that you have online accounts for
- Any website that has your credit card information
- Your Google account
- Your social media accounts
Then over time you can migrate your other accounts as well.
You owe it to your family to get a password manager
Section titled: You owe it to your family to get a password managerIf you died tomorrow, would your spouse/descendants know how to get into your bank account? Your credit cards? Your investment accounts? Would they even know what company to call about getting access? That discovery process puts an incredible burden on them at the worst possible time.
Your password manager can act as your family’s online home base. It organizes your digital life. Not only are urls and credentials in there, but you can add account numbers, notes, phone numbers, and important dates. You can even add a finance tag to all money related things so they can be found with one click.
Please consider using a password manager. There is a real possibility of one of your accounts getting hacked, if one hasn’t already.
It will give you the confidence to go back to sleep next time you get one of those “Did you just try to login?” emails. It will prevent a MySpace leak from letting someone into your bank because you forgot you used the same password. It will stop you from having to reset passwords all the time. It will make it easier to share your Hulu password with your sister. It could help your spouse in their most vulnerable moment.
Stay safe out there.
Send this to a friend who needs a password manager
Section titled: Send this to a friend who needs a password managerKnow someone who’s still cycling through the same three passwords everywhere? Pop their name in below to create a personalized version of this post:
Personalized link
https://olivare.net/blog/password-manager-
Any password can be brute forced if given enough time. But by making your password sufficiently complex, you can ensure that it will take a hacker with an extremely fast computer years to guess your password. If the website declines access after
nnumber of incorrect entries, then this strategy can take centuries. This ability to eventually guess any password is why some places require you to change your password every so often. ↩ ↩2 -
In addition to a master password, 1Password also utilizes a Secret Key. This is a long, complex value generated by 1Password so that even if your master password leaves something to be desired, your data is secure. The Secret Key is used alongside your master password to encrypt your secret data, so that both are required to decrypt it. ↩