Skip to content
Practical technology, explained simply

Learn · security

How to store your passwords safely

A simple system to stop reusing passwords, protect your important accounts, and get back in without improvising.

Ibrahin·Published on 2 September 2026·4 min read

Text drafted with artificial intelligence. The topic, the angle and the final review are Ibrahin's. How AI is used here

A phone propped against a laptop, with the outline of a padlock on its screen, on a table in the dark.
Illustration, not a real screenshot.

A password that is hard to remember is not a system. If you reuse it, a leak at one website can open the door to your email, your photos or your purchases. The practical answer is not memorising twenty passwords: it is using a different one for every service and protecting the main way in.

Short answer

Use a password manager you trust, create a long and unique master password, change the reused passwords first, and turn on two-step verification on your email and your important accounts.

The rule that changes everything

Every service should have a different password. That way, if a shop suffers a leak, that password is no use for getting into your email. There is no such thing as a password “just for unimportant sites”: an apparently minor account may use the same email address to recover the others.

The manager takes care of creating and remembering long passwords. All you have to protect is the master password and the recovery methods. Do not keep that password in an unprotected note, and do not send it in a chat.

Step 1: protect the main email account

Email is usually the key that resets the other accounts. Start there:

  1. Change the password if it has been reused.
  2. Turn on two-step verification.
  3. Check the recovery phone numbers and addresses.
  4. Review open sessions and devices.
  5. Look for forwarding rules you did not create.

Do it from the official site or app, not from a link you received in a message.

Step 2: decide how you will store the passwords

A manager can be a dedicated app, a feature built into your system, or a solution provided by an organisation. What matters is that it can generate unique passwords, sync in a way whose risks you understand, export your data if you need it, and recover the account through a clear procedure.

Do not choose on a feature list alone. Check who provides it, what happens if you lose your device, what recovery options exist, and how it is updated. If you do not understand the recovery process, you have not finished choosing.

Step 3: create a master password you can protect

The master password has to be long, unique and used nowhere else. A phrase made of several words you can remember may be more manageable than a short string of symbols.

Do not paste it into a chat, an email or a form to test the manager. Also decide how you will keep it when you do not have access to your device. A recovery copy should be protected and kept separately, not hidden in an unprotected folder.

Step 4: change accounts in order

You do not have to do it all in one afternoon. Follow this order:

  • main email;
  • banking and payments;
  • Apple, Google or Microsoft;
  • social networks and messaging;
  • shopping, work and storage;
  • everything else.

On each account, generate a new password, turn on two-step verification, and close any sessions you do not recognise. Save the change in the manager, and do not keep a parallel list in a text document.

Step 5: add a second barrier

Two-step verification makes access harder even if someone knows your password. It can use a code app, a security key, or another method the service offers. Keep the recovery codes somewhere other than your main phone, and make sure you know how to use them.

Do not share a sign-in code with anyone. Legitimate support never needs you to read one out over the phone or in a message.

What to do with old passwords

Do not keep them out of convenience if you no longer need them. If you are closing an account, go in through the official channel, download whatever you need, and remove the access using the service’s own options. If an account stays active, change the password and check the recovery settings.

If you suspect a password has leaked, change it on that service and everywhere else you reused it. Review sessions, connected apps and recent activity.

Common mistakes

Only changing the password

An open session or an authorised app can keep the access alive. Revoke anything you do not recognise as well.

Using easy variations

Changing the last digit does not create an independent password if someone can guess the pattern.

Depending on email for everything

Protect the email first and keep the recovery methods up to date. If you lose that key, everything else gets harder.

Keeping the master password next to the phone

A copy should help you recover, not let anyone who finds the device get into everything.

What I would do

I would start with email, banking and whichever account holds my photos or documents. I would not try to migrate a hundred services at once: I would change five, check that recovery works, and carry on with the next group.

Checklist

  1. Does every important account have a different password?
  2. Does the main email have two-step verification?
  3. Do I know where the recovery codes are?
  4. Have I closed sessions and apps I do not recognise?
  5. Can I get back in without depending on a single thing?

Sources

Review

Responsible for publication: Ibrahin. Date: 2026-09-02. Last checked: 2026-09-02.