6 Critical Password Mistakes You’re Probably Still Making
tete_escape / Adobe Stock
Toggle Dark Mode
Passwords have been around for decades, but they’re still one of the biggest weaknesses in online security.
What’s worse, nowadays, the problem isn’t always that people choose passwords like 123456; you can create an extremely strong password and still put several accounts at risk just by making a couple of mistakes that many people don’t even know they’re making.
Online security has also changed considerably over the years. Now there are many ways to make your accounts safer besides having a strong password. Things like multi-factor authentication and password managers make things easier for us, but that doesn’t mean you should let technology handle everything for you. If you want to make your accounts extremely safe, here are some of the worst mistakes you need to avoid.
You’re Reusing the Same Password Everywhere
We get it: having multiple passwords can be challenging. After all, how are you supposed to remember every password you use? Instead, using one really strong password for every account may seem reasonable. If nobody can guess it, why bother creating another one?
The problem begins when someone does guess your password — or more likely gets a hold of it in some other way. Data breaches are sadly more common than you might think, but you may also accidentally share your credentials in the wrong place at the wrong time. When hackers get that data, they’ll use your combination of email and password on other websites until they hit a possible match.
Your original password could be extremely long and impossible to guess, but that strength won’t help once someone already knows it. Reusing it can turn one company’s security failure into a problem for all your online accounts.
Of course, it is pretty tough to memorize all your passwords, which is why it’s best to use a password manager. Your iPhone already comes with a remarkably powerful one for free, but there are plenty of other options if you want more advanced features.
If you don’t want to use a password manager or have a completely different password for every website, at least use a unique password for your most important accounts. Your personal email, banking accounts, and the platform where you store your data in the cloud should all have strong and unique passwords. That way, it’ll be harder for criminals to hack into other accounts if they manage to get into one of your accounts.
You Keep Using Short Passwords
It’s basically a joke at this point, so we know we should never use “password” as our actual password, but that’s just the tip of the iceberg. Using a password such as “Blue21!” might look good enough because it contains several types of characters. However, it’s still extremely short, which limits the number of possible combinations an attacker needs to consider.
Yes, size matters — at least when it comes to your passwords. has become an important part of modern password guidance. The National Institute of Standards and Technology (NIST) requirements call for a minimum of 15 characters when a password is used as the only authentication factor. The longer the password, the harder it is to crack.
You don’t need to create something impossible to type. A passphrase made from several unrelated words can give you the right length without becoming difficult to remember. And of course, avoid famous quotes or predictable expressions that someone else might think of too. So no using favorite songs, speeches, or poems. If someone knows you a bit too well, they might try using that first.
Ignoring Compromised Password Warnings
This is a huge mistake that many of us are guilty of. An account may look completely normal even after its password has leaked, but that doesn’t mean you can safely ignore the warning.
Leaked credentials can circulate across the web long before someone uses them against your particular account. Attackers may also save large collections and test them automatically across different services.
The worst part about this is that your iPhone alerts you of these issues. When you use a password, you might get an alert saying that those credentials have been compromised and that you should change them as soon as possible. Additionally, if you go to the Passwords app and tap on the Security section, you’ll see a message with a list of all the passwords that have been leaked.
However, most of us just ignore it because we have other things to do or just don’t feel like doing it at the moment. But if you ignore it for too long, you might regret it in the future. Instead, try to find the time to update all your leaked passwords so you aren’t a target. Your future self will thank you for it.
You’re Still Relying Only on Your Password
It doesn’t matter how long or difficult your password is; it can still be stolen by anyone. And that’s where multi-factor authentication comes in, as it gives an attacker another obstacle to overcome. And this one might be a bit harder.
MFA requires another form of verification in addition to the password. Depending on the platform or service, this might come from an authenticator app, a text message, or a hardware security key.
This makes it way harder for anyone to access your account, as you’ll be alerted when they use your credentials.
There are plenty of multi-factor authenticators, and the most popular websites all offer them in some form. Sending a code to your email or phone via SMS are the most popular methods, although they have their drawbacks — a hacker who already has your credentials could be in your email account, and SIM swapping scams are still a problem. For the best security, we recommend using a two-factor authentication app such as Google Authenticator.
Still, any type of MFA is better than none at all, as these provide a stronger wall of security that’s harder to crack. So go to all your accounts and turn on MFA on every account you have.
Start with your most important accounts, like your email and financial accounts. Then protect cloud storage and social media. Then take care of the other platforms that you use.
Saving Passwords in Notes or Screenshots
This is a huge and very common mistake, and if you’re someone who saves passwords on their iPhone, you should stop now. Sure, keeping all your passwords inside a note may feel convenient, but it’s really a bad way to store your most important credentials.
Both text and images can be easily shared. If you lend your iPhone to a coworker for a quick call, they might (accidentally or intentionally) find your passwords. Or, if someone steals your iPhone and manages to unlock it, they’ll have access to all your digital life. Both situations would suck, and they’re also easily avoidable.
So if you have a hard time keeping track of all your passwords, the best thing you can do is use a password manager. Apple’s Passwords app is a great alternative, as it works perfectly on all your Apple devices and it’s already built in.
There are also a ton of third-party password managers that you can use on your iPhone and basically any other operating system like Android or Windows. As long as you choose a reputable app, you’ll be better off than using your Notes app or taking a screenshot.
Ignoring Passkeys When They’re Available
Passwords can have many weaknesses, and even if they don’t, they can always get leaked or accidentally shared with the wrong person.
Luckily, there’s been a new way to authenticate yourself in the last few years called Passkeys. They use your device instead of asking you to enter your password every time you want to log in. Basically, your device creates a digital key that’s unique for each specific website and that only you can access by using your face, fingerprint, or your passcode.
On your iPhone, you can authenticate yourself with Face ID. Your device confirms that you’re authorized to use the passkey without the need for another password.
Passkeys also resist conventional phishing attacks because they’re tied to the legitimate platform. Phishing attacks often redirect you to a fake website with a similar design to steal your credentials. But if you use a passkey, the fake website simply can’t convince your password manager to authenticate it as another domain.
When a trusted service supports passkeys, consider using it. Apple Passwords can store supported passkeys and sync them across your Apple devices, so it’s easier to log in to your accounts no matter which device you’re using.
Keep Your Passwords Safe
Protecting your accounts doesn’t require you to have an annoying and elaborate password system. In fact, trying to make your own clever system often creates predictable patterns that really good attackers can recognize.
Instead, you need to find a way to keep things simple and secure enough for you. By avoiding the mistakes on this list, you’ll be able to create stronger passwords and make your accounts safer than before. Of course, nothing is really unhackable, but the harder you make it for criminals, the less likely you are to have security problems.





