Passwords without panic: how to protect your accounts and keep access

A practical guide to passwords, secure sign-ins, breach checks and account recovery.

Reviewed by a digital security specialist: .

Service settings and features change. Choose security measures that fit your circumstances.

Contents

Email, messaging apps and social media hold a great deal of personal information: conversations, photos, documents and the contact details of people close to us. For LGBTQ+ people, a leak can also mean being outed without consent. Securing your accounts can help reduce these risks. You can start with a few manageable steps.

One account, one password

A strong, unique password for every account and two-factor authentication wherever available are the basics of digital security.

Reusing a password is convenient but risky: after a breach at one website, attackers may try it elsewhere. Small changes, such as adding the service's name, do not make this approach reliable.

You do not have to invent and remember dozens of different passwords. A password manager handles this for you: it is an app that generates random combinations, stores them and helps fill them in when you sign in. You do not even need to know the individual passwords — just remember one master password for the vault. Make it long and unique, for example by using randomly selected words rather than a familiar quotation.

A password manager does not replace device security: malware can capture what you type and access an unlocked vault. EFF's guidance.

Which password manager should you choose?

The main choice is whether you want synchronisation across devices or prefer to keep your database locally. These three options include free tools; we considered their security design and independent assessments when selecting them.

Bitwarden — for passwords on both your phone and computer. The free plan lets you store unlimited passwords and synchronise them across devices. A paid subscription adds features, but you do not need it to get started. Its source code is open, and the company publishes information about external security assessments. The vault is encrypted before being sent to the server. Using a cloud service still involves trusting its apps, updates and infrastructure. Features and plans.

KeePassXC — for keeping your database locally. This free, open-source application runs on Windows, macOS and Linux. It stores passwords in an encrypted file and does not require an account with a provider. The project has undergone independent assessments; its certification from France's cybersecurity agency ANSSI specifically covers version 2.7.9 on Windows 10, not every version or platform. You will need to arrange backups and transfers between devices yourself. KeePassXC has no mobile app of its own: compatible mobile apps need to be chosen separately. Project website.

1Password — a paid option with synchronisation. There is a free trial but no permanent free personal plan. Alongside your account password, a randomly generated Secret Key helps protect your vault if encrypted data is stolen from the server. The company publishes information about independent audits. Plans.

If you are unsure which to choose, the free Bitwarden plan is a reasonable starting point. Install your manager through its official website and keep it updated. Enable additional sign-in verification for the vault itself where available — we explain this next.

Add another way to verify sign-ins

Two-factor authentication requires an additional check alongside your password when signing in. If the password leaks, it may not be enough to access your account.

When you have a choice, an authenticator app or a hardware security key is preferable to SMS. One-time codes can still be tricked out of you: never share them with someone claiming to be support staff.

With Russian phone numbers, it is especially important not to rely on SMS if you face a risk of state persecution. These messages depend on the mobile operator's infrastructure: a long password does not protect the channel delivering the code. Cases have been reported in Russia in which activists' accounts were taken over while SMS delivery to their numbers was disabled. This does not mean that every Russian number is compromised, but it is an additional reason to choose verification that does not depend on SMS.

Keep recovery codes somewhere safe that you can access without a lost phone. Security should help you retain access rather than lock you out of your own account. EFF's guide.

What are passkeys?

Some services offer passkeys. Instead of typing a password, you confirm the sign-in on a device, for example with its unlock code or your fingerprint. The key is tied to the specific service: a fake website cannot obtain it in the same way as an ordinary password.

Before setting one up, check where it is stored, whether it synchronises and how you would sign in after losing your device. Secure sign-in and reliable recovery are equally important. Passkeys explained by the FIDO Alliance.

How to protect Telegram

Enable both Telegram's two-step verification password and the app's local passcode. They serve different purposes and do not replace one another. You will usually find both under Privacy and Security, although labels may differ between app versions.

The two-step verification password protects sign-ins on a new device. It is also known as the cloud password. Telegram asks for this password in addition to the verification code, so the code alone will not be enough. Choose a strong, unique password and add a securely protected recovery email address.

The app passcode helps keep conversations locked on your device. It is useful, for example, if someone gets hold of your unlocked phone. Set it separately on each device where you use Telegram and enable the app's automatic lock. This passcode does not prevent someone from trying to sign in to your account on their own phone — that is what the two-step verification password is for.

Also check connected devices. Under Devices, review where your account is already signed in and terminate any unfamiliar sessions. Check this list periodically: enabling protection for new sign-ins does not automatically close an existing session on someone else's device.

Check whether your email address appears in a breach

Have I Been Pwned lets you check an email address against breaches known to the service, free of charge. Enter the address; you do not need to provide your email password for this check. Look at which service was affected and what types of data were exposed. You can also subscribe to notifications of new breaches.

A match does not mean that your email account itself was hacked: the address may have appeared in a database from an online shop or another site you used. If a password was exposed, change it on the affected service and anywhere else you reused it. If you have already replaced it with a unique password since that breach, the old result does not by itself indicate a new compromise.

No results is not a guarantee of safety either: the service does not know about every breach. Some sensitive records are only shown after you verify ownership of the address. The check involves sharing your email address with a third-party service, which is worth considering if the address itself is particularly sensitive.

If you want stronger protection

Once the basics are in place, you can go further, particularly if your accounts contain sensitive conversations or you are concerned about targeted attacks.

Your quick action list

  1. Start with your main email account. Set a unique, randomly generated password and enable two-factor authentication. Then repeat this for other important accounts.
  2. Replace reused passwords. Generate and store new ones in a password manager.
  3. Choose a sign-in method that does not depend on SMS where available: a passkey, hardware security key or authenticator app. If SMS is the only option, it is still better than no additional protection.
  4. Enable both Telegram protections: the two-step verification password for new sign-ins and an app passcode with automatic locking. Terminate unfamiliar sessions under Devices.
  5. Keep a way back in. Store recovery codes somewhere safe that you can reach without your main phone, and check your recovery email account.
  6. Check your email address on Have I Been Pwned. If a breach includes a password of yours, replace it wherever you still use it.

You do not have to do everything in one evening. Start with one important account: protection you actually use is more helpful than a perfect plan put off until later.