Highlighted wordsare glossary terms — tap one for a plain-language definition.
Good digital hygiene means building a few protective habits that stay useful even as the technology changes. For accounts, the whole idea fits into three words. Unique: important accounts don't share a password. Layered: use the strongest practical sign-in the service offers. Recoverable: keep a safe way for you — the real owner — to get back in.
One account. One lock.
Reusing a password means a break-in somewhere unimportant can become a problem somewhere that matters. Criminals use automated systems to try stolen email-and-password combinations on other websites — this is called Credential stuffingWhat it means: Automated attempts to use leaked username-and-password combinations on other websites.Example: An old leaked password still unlocking your shopping account years later.What to do: Give every account its own unique password.Important: One reused password can expose dozens of accounts at once.What does this mean?. So a password exposed at one company can threaten your other accounts if you reused it. The fix isn't heroic: it's one lock per door.
- Give every important account a credential used nowhere else.
- Where a service offers a PasskeyWhat it means: A phishing-resistant way to sign in using cryptographic credentials stored or managed by a trusted device or credential provider, instead of typing a reusable password.Example: Unlocking an account with your fingerprint, face, or device PIN — nothing to type.What to do: Consider a passkey when an important account offers one, starting with your email.Important: Keep a device lock and a backup sign-in method in case you lose the device.What does this mean?, consider it instead of relying only on a reusable password.
- Adding a “1” or “!” to the end does not make it a different password.
- Start with email, banking, and your Password managerWhat it means: Software that generates, stores, and fills unique account passwords, and may also manage passkeys or other credentials.Example: The manager generating and filling a 20-character password you never have to recall.What to do: Set one up and move your email, banking, and cloud passwords into it first.Important: Protect it with one strong passphrase plus MFA, and never share that passphrase.What does this mean? — then work outward.
Long. Unique. Never reused.
Password strength is mostly about length and uniqueness, not about forcing in an uppercase letter, a digit, and a symbol. Composition rules push people toward predictable patterns, and calendar-based changes every 30, 60, or 90 days mostly produce a bumped number on the end. Current NIST guidance asks services to drop both, and to screen new passwords against lists of previously breached ones instead.
- If you create a password yourself, make it long and unique — aim for at least 15 characters.
- A passphrase of several unrelated words is easy to remember and long by nature.
- Change a password when there's a reason — suspected compromise, a breach notice, or a policy that requires it — not on a schedule.
- Skip security questions where you can, or answer them with random text stored in your password manager.
What a password manager actually does
A password manager generates and stores different passwords for your accounts so you do not have to memorize dozens of unrelated passwords. For most accounts, letting a reputable manager generate a long, random, unique password is easier and safer than inventing one yourself. It also fills passwords only on the matching website, which quietly catches some lookalike pages.
- Look for one that works across your devices and generates unique passwords.
- It should support secure sync, Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean? on the vault itself, and passkeys where available.
- Check that its recovery options make sense to you before you rely on it.
- The best one is the one you will realistically use every day.
What is a passkey?
A passkey lets your device prove that you are authorized to enter an account without requiring you to type a reusable password into the website. You may unlock a passkey using your fingerprint, face, device PIN, or another device-level method. Passkeys are designed to resist many common PhishingWhat it means: A deceptive email or message designed to make you click, share information, send money, or give account access.Example: An “unpaid delivery fee” text with a link to a page that looks like the post office.What to do: Don't tap links in unexpected messages — open the company's app or type its address yourself.Important: Real companies never ask for your password or a login code by message.What does this mean? attacks, because the important credential is tied to the legitimate service rather than something you type into a convincing fake login page. Passwords haven't disappeared — most of us live in a mixed environment of passwords, password managers, passkeys, authenticator apps, device approvals, security keys, and SMS codes.
- Hygi Habit: if an important account offers a passkey, don't dismiss it just because it's unfamiliar — read what the service is offering and decide whether it suits you.
- Keep a screen lock on any device that holds passkeys.
- Set up a second sign-in method so a lost device doesn't lock you out.
- A passkey is not just another password — there is nothing reusable to type or hand over.
The MFA ladder: pick the strongest practical rung
Strongest practical protection: passkeys or FIDOWhat it means: A family of open authentication standards designed to enable stronger, phishing-resistant sign-in methods.Example: A tap-to-approve security key described as “FIDO2 compatible”.What to do: Where a service lists FIDO or passkey sign-in, treat it as its strongest option.Important: FIDO is the standard behind passkeys and security keys, not a brand or an app.What does this mean?/WebAuthnWhat it means: A web authentication standard used by browsers and websites to support public-key credentials such as passkeys and security keys.Example: A site asking your browser to “use your passkey” — WebAuthn is what makes that work.What to do: Keep your browser and phone updated so passkey sign-in works reliably.Important: You rarely see the word in daily use; it's the plumbing behind passkeys.What does this mean? security keys — these are designed to resist phishing because authentication is connected to the legitimate service. Strong: authenticator apps and secure device-approval methods — substantially more protection than a password alone, though manually entered one-time codes can still be stolen through phishing. Better than a password alone: SMS/text VerificationWhat it means: Confirming a request through a separate, trusted method.Example: Calling the number on the back of your card instead of the one in the message.What to do: Save official phone numbers and app logins now, before you need them.Important: Never verify using contact details supplied in the suspicious message itself.What does this mean? — real protection compared with password-only login, but more vulnerable than phishing-resistant methods. If a stronger practical method is offered, consider using it.
- Turn on the strongest option each service actually supports.
- Never turn SMS codes off if the alternative is password-only sign-in.
- Manually typed authenticator codes are strong, but they are not phishing-resistant.
- No method makes an account unhackable — layers reduce risk substantially, and that's the goal.
A verification code is a key.
A code sent to you is for you to enter — not for a stranger to collect. Say you get a call claiming to be from your bank, and during the call a six-digit code appears on your phone; the caller asks you to read it aloud. That is the moment to stop. Do not provide the code. End the incoming communication and contact the bank yourself using a number or app you already trust. Pause. Leave the message. Verify.
- Only enter a code into a page or app you opened yourself.
- No legitimate representative needs you to read a code back to them.
- If a login-approval prompt appears and you did not start a login, do not approve it just to make it stop.
- Repeated unexpected prompts (MFA fatigueWhat it means: Repeated login-approval prompts sent to pressure someone into approving a sign-in they did not start.Example: A stream of “Approve this login?” notifications at 2 a.m.What to do: Don't approve it. Change the password from a trusted device and review account activity.Important: Repeated prompts usually mean someone already has your password.What does this mean?) usually mean someone has your password — change it from a trusted device.
Your master key account
Your primary email account may be used to reset passwords for many other services. That makes it one of the most important accounts to protect. Your primary email password should never be reused anywhere else.
- Give it a unique credential, and add a passkey if the provider offers one and it suits you.
- Turn on the strongest MFA it supports.
- Keep the recovery phone and recovery email current, and save any recovery codes it offers.
- Read unexpected sign-in alerts instead of dismissing them — check the account through the app, not the alert's link.
The Hygi Five-Door Reset
You don't have to secure every account today. Start with five accounts that would matter most if someone else gained access, and run each through Unique, Layered, Recoverable.
These checkboxes stay on this device. Never type an account name, password, passkey, verification code, or recovery code into Hygi.
0 of 15 checks done
Why Hygi. recommends this — the guidance above follows these published sources:
NIST
SP 800-63B-4: Digital Identity Guidelines — Authentication and Authenticator Management (July 2025)(opens in a new tab)Password length over composition rules, no scheduled changes, breach blocklists, phishing resistance, authenticator and recovery management.
NIST
Cybersecurity consumer guidance: passwords, password managers, passkeys and MFA(opens in a new tab)Plain-language consumer framing for long passwords, managers and multifactor sign-in.
CISA
Implementing Phishing-Resistant MFA(opens in a new tab)Relative strength of FIDO/WebAuthn, authenticator apps and SMS.
CISA
Secure Our World — Use Strong Passwords and Turn On MFA(opens in a new tab)The consumer habits this lesson is built around.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary