Introduction

Most account takeovers start with a weak or reused password. This checklist covers both the basics you should do today, and passkeys, a newer, stronger option you can start adopting account by account.

Part 1: Fix Your Passwords (10 minutes)

 Make each password at least 12 characters: mixing upper and lower case, numbers, and symbols.

 Never reuse a password across accounts: if one site is breached, a reused password lets attackers into everything else you used it for.

 Avoid personal details: birthdays, pet names, phone numbers, anything a stranger could find on your social media.

 Use a password manager: (like Bitwarden, 1Password, or your browser’s built-in manager) so you don’t have to remember dozens of unique passwords.

  Turn on two-factor authentication (2FA): on every account that offers it, especially email, banking, and social media. This adds a second check beyond just the password.

 Change any password you’ve reused: starting with your email account (since email is often used to reset everything else).

Part 2: Move to Passkeys Where You Can (5 minutes per account)

Passkeys replace your password entirely with your device’s fingerprint, face unlock, or PIN. They can’t be phished the way a typed password can, since there’s no password to trick you into typing.

 Update your devices and browser: to the latest version, passkey support needs current software.

 Check which of your accounts already support passkeys: Google, Microsoft, Apple, and many banking apps now offer this option in account security settings.

 Set up a passkey for your most important accounts first: email, banking, and any account tied to financial or identity information.

 Keep your password as backup: where the service still requires one, but rely on the passkey for day-to-day login.

Quick reference: which matters most, right now?

    1. Turn on 2FA everywhere you can — this is the single highest-impact step.
    2. Fix any reused password, starting with email.
    3. Set up a password manager if you don’t have one.
    4. Add passkeys to your top 2-3 accounts as you get comfortable with them.