TechCompare LogoTechCompare

The 5 most common password mistakes and how to fix each one today

All five mistakes are fixed by two tools: a password manager and 2FA. Set them up once. The time investment is 10 minutes. The security improvement is orders of magnitude.

The five most common password mistakes, in order of how often they lead to account compromise: password reuse across sites, using short passwords (under 12 characters), sharing passwords over unencrypted channels (text message, email), storing passwords in unencrypted notes (phone Notes app, desktop sticky notes, spreadsheet), and not enabling 2FA on critical accounts.

By TechCompare · Updated

Security domain
Best Practices
Practical password security advice
Topic focus
Password mistakes
password-mistakes

How this is calculated

Password reuse is the number one cause of account takeover. One breached site exposes the password, and attackers try it on every other service. A password manager fixes this instantly by generating unique passwords. Short passwords are crackable by GPU clusters in hours to days. The fix is simple: use 16+ characters. Sharing passwords via text or email leaves a permanent unencrypted copy on the recipient's device, your device, and the service provider's servers. Use a password manager's secure sharing feature or an encrypted messaging app with disappearing messages. Storing passwords in unencrypted notes means anyone with access to your unlocked phone or computer can see them. Password managers encrypt at rest. Skipping 2FA leaves you with single-factor authentication. Enable it on email, banking, and any account with payment methods.

Verdict

Two tools close every one of the five failure modes. Reuse dies because the manager generates a fresh string per account. Short passwords stop because 16 characters is the default. Unencrypted sharing gets replaced by the manager's secure-share feature. Storing in Notes or a sticky note gives way to an encrypted vault. And missing 2FA is a one-time toggle. The whole setup runs in about 10 minutes and pays off the first time a non-critical site breaches.

More Passwords scenarios

Frequently asked questions

What is the single worst password habit?
Reuse. One breached site hands attackers the email and password pair, and bots then try it on your bank, email, and every high-value service within hours. Reuse is what turns one forgotten forum account's leak into a full identity compromise. A password manager kills the habit by making every password unique by default.
Is it safe to store passwords in my phone's Notes app?
No. Notes apps store content unencrypted or synced in the clear, so anyone who borrows your unlocked phone, or compromises the cloud account the notes sync to, reads every password. A password manager encrypts the vault at rest and locks it behind your master password, which is the difference between a list and a safe.
How do I share a password with family securely?
Through the password manager's sharing feature. Bitwarden, 1Password, and Proton Pass all let you send a credential to another vault encrypted end-to-end, with expiring links when the recipient doesn't have an account. Texting or emailing a password leaves a permanent unencrypted copy in every device and server the message passes through.