ClearPath PublishingGuides for real life

Guide 01  ·  Outsmart the Scammers

Why Your Password Is Probably Putting You at Risk

There is a good chance you have a password you have used for years. Maybe it is a pet’s name, or a birthday, or a word with a number stuck on the end. Maybe it is written in a notebook next to the computer. And maybe you use the same one in a few different places, because remembering more than one felt like too much to ask.

None of that makes you careless. It makes you like nearly everyone.

But it is worth fixing, and the fix is smaller and simpler than you have probably been led to believe. You do not need to understand how any of this works. You need to change two or three things, once.

The habit that causes the most damage

It is not weak passwords. It is repeated ones.

Here is what happens. Companies get broken into all the time — stores, airlines, insurance companies, anywhere you have ever made an account. When that happens, the criminals walk away with a list of email addresses and passwords.

Then they do the obvious thing. They take that list and try every combination at the big banks, at the email providers, at the shopping sites. It costs them nothing to try. They are not targeting you personally. A computer is doing it, thousands at a time.

So if the password for your email is also the password for your bank, one break-in at a company you barely remember signing up with becomes a break-in everywhere.

This is why the single most valuable thing you can do today is make your email password different from every other password you have. Not stronger. Different.

Your email is the master key. Almost every website in the world will let someone reset your password by sending a link to your email. Whoever controls your email controls everything else.

What actually makes a password hard to break

For years we were told to use capital letters, numbers, and symbols. That advice was never very good, and it has aged badly.

A criminal is not sitting at a desk guessing. A computer is trying millions of combinations a second, and it already knows every trick people use — swapping a zero for the letter O, putting an exclamation point at the end, adding the current year.

What actually defeats that computer is not cleverness. It is length.

Four ordinary words strung together beats eight characters of symbols, and it is not close. Something like cinnamon garden ladder river is long enough to be genuinely difficult and short enough to remember. Picture the four things together and it sticks.

Two conditions. The words should have nothing to do with each other, and they should not come from a song, a saying, or a Bible verse. Those are the first things the guessing programs try.

About writing them down

You have probably heard that you should never write a password down.

That advice was written for offices, where the danger was a coworker reading a sticky note on your monitor. It does not describe your situation.

The person trying to get into your accounts is not in your house. They are on another continent, and they will never see your notebook. A notebook in a drawer is far safer than using one password everywhere.

So write them down. Use a small notebook, keep it somewhere out of sight, and tell one person you trust where it is. That is a real, workable system, and it is used by plenty of people who are perfectly safe online.

If you would like something tidier, there are programs called password managers that remember everything for you and fill it in automatically. Bitwarden and 1Password are the two most recommended, and both have free versions. They are genuinely good. But they take about half an hour to set up, and that is a job worth asking an adult child or grandchild to do with you rather than alone.

Either way works. Choose the one you will actually keep using.

The second lock on the door

Even a good password can be stolen — a fake website, a stray click, a company that did not protect your information.

That is why it is worth turning on the second step: the code your bank or email sends to your phone when you sign in. With that turned on, a stolen password is not enough. The thief would also need your phone in their hand — which is also why it is worth checking a few settings on the phone itself.

It takes about five minutes per account. Turn it on for your email and your bank first. Ask a family member to sit with you and do them both in one sitting.

And a warning that matters more than anything else in this article: once you have those codes turned on, never read one aloud to someone who calls you. No bank, no government office, and no company will ever call and ask you for that code. Anyone who does is a criminal, and that code is the last thing standing between them and your account. This is one of the most common scams there is, and it works because the caller sounds calm, official, and helpful.

Where to start

You do not need to fix everything this week.

Start with your email. Give it a long, unique passphrase, write it down, and turn on the phone-code step.

Then do the same for your bank.

Then, over the next few weeks, work through anything else that has your money or your personal information in it. Everything else — the crossword site, the recipe newsletter — genuinely does not matter much.

Two accounts, one afternoon, and one family member to help. That is the whole job.

From the book

Outsmart the Scammers

Get the free preview chapter — the introduction plus “Why You, Specifically” — and learn how scammers choose their targets.

Get the free preview