Skip to content

How do password managers work?

Security guidelines state that all accounts, regardless of their importance, should use unique and complicated passwords. Unfortunately, the burden of juggling different accounts with long passwords that are difficult to keep track of or enter without typos leads to people settling for simpler, repetitive, and far less resilient passwords. 

This struggle can be easily solved once you know how password managers work to support your credential handling. Whether it’s a built-in browser password manager or a dedicated third-party tool, they let you conveniently keep track of your credentials without losing out on that security factor. Let’s look into how password managers actually work, what features they may offer, and what makes them a safe choice to store all sensitive details in one place.

What is a password manager?

Password managers are pretty self-explanatory—they’re tools that let you store and manage your login credentials. They do the heavy lifting for you by storing your essential login information, such as your usernames, passwords, and email addresses.

Even if the term doesn’t ring a bell, chances are you’ve already used one before. Browsers like Chrome, Firefox, and Opera have built-in password managers that let you save your login details, saving you time whenever you need to log in. Third-party password managers are generally regarded as a more secure alternative to their browser counterparts.

What does a password manager do?

The primary purpose of a password manager is to provide secure storage for sensitive information. This is achieved through encryption—the process of scrambling data so that it can only be accessed if you have the right key to decipher it. A password manager like NordPass encrypts information on your device and, once it’s scrambled, sends it to the servers for safekeeping. This helps ensure that even in the case of a breach, the data is not accessible to unauthorized parties in plaintext.

As for the data itself—despite the name, password managers are not limited to passwords alone. They also provide storage for email addresses, personal addresses, ID information, banking details, and any other sensitive data that you want to keep safe. Password managers can even provide storage for passwordless solutions—NordPass lets its users store and manage passkeys.

Secure storage is just the tip of the iceberg. By now, password generators are a basic requirement for both browser-based and standalone password managers. Password generators help easily create unique and complex passwords that meet the standards of various security protocols. Instead of coming up with a password yourself, you can have the password manager generate a random, one-of-a-kind string of characters for you.

Password managers can take the chore out of finding the right password for the right account. Although you can use the vault search function or sort your credentials alphabetically when you need them, password managers eliminate this manual step altogether with autofill. This function instantly finds the login credentials you need and inputs them for you, instantly letting you access your account. Additionally, autosave detects whenever you’re entering credentials that aren’t in your vault and lets you store them without needing to type them out yourself.

 

Family password management

We usually focus on the benefits password managers offer to individuals. But did you know that you can share this tool with your friends and family and keep your entire closest circle protected online?

A password manager facilitates secure and convenient credential sharing. Imagine a family of five using a single Amazon account but scattered across different households. Using a password manager like NordPass, they can securely juggle access to the shared account. No need to send an unencrypted text message, a screenshot, or spell it out over the phone—you can simply select the password you want to share, who you want to share it with, and what access permissions you want to grant.

Managing passwords within a family is also convenient for broader security. Setting up a NordPass Family account grants access to Premium features like the Data Breach Scanner, which tracks the dark web for any signs of leaked personal information, and Password Health, which lets you know if any of your passwords are old, weak, or reused.

Multiply that by six, and you have your family’s cybersecurity sorted. And don’t forget, a family password manager doesn’t mean it has to be your relatives only—you can bring your spouse or friends along for the ride.

Business password management

Have you ever given in to the temptation to reuse one of your personal passwords for a work-related account to save time? It wouldn’t be surprising—between juggling accounts for personal and professional use, an average person has to handle 168 and 87 passwords, respectively.

A business password manager is here to keep things simple and separate personal and work credentials. It helps organizations optimize their workflows and implement centralized password usage policies that uphold high security standards.

Many features related to corporate credential security are handled from the admin side of password managers. For example, using NordPass, security managers can establish password strength requirements, such as password length, use of special characters, and frequency of updates.

Companies can set up extra layers of security, like multi-factor authentication, across the company. Additionally, NordPass offers a built-in Authenticator, allowing employees to easily generate two-factor codes for their work accounts and access login credentials all in one place.

As for employees themselves, they can handle their work-related accounts, such as corporate emails, social media communications, or banking. They can also securely share credentials with their colleagues or clients for collaboration.

NordPass allows Business users to control their shared access permissions to maintain data security. No need to fear losing track of what’s been shared—the Activity Log gives a clear overview of who created, edited, or granted access to credentials.

How to use a password manager

The hardest step in getting started with a password manager is finding the right one for you. The core will be similar everywhere—all you need to do is create an account, set up a master password, and add credentials to your encrypted vault. And if you’re looking for additional security for your cyber life, look no further than NordPass.

Whether you’re looking to cover your own personal needs, handle sensitive work-related data, or share passwords more securely with your friends and family, NordPass offers something for everyone. It’s built on zero-knowledge architecture and uses XChaCha20 encryption to provide a high level of security for both your personal and professional sensitive data. Start your hassle-free digital life with NordPass—a password manager that puts convenience first without compromising your security.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

How to disable the Firefox password manager

Like other major browsers, Firefox offers a convenient built-in way to store your passwords. It’s beloved by users for being a non-Chromium alternative to the market leader Chrome. However, if you find that Firefox is not the browser for you or want to look into different credential storage methods, you might want to know how to disable the Firefox password manager first.

Today, we’ll cover the process, from exporting your passwords for safekeeping to switching off the password manager on desktop and mobile devices. Then, we’ll see what secure alternatives you can use to store and access your credentials.

Some steps before you turn off the Firefox password manager

Firefox allows users to save login details whenever they log in to a new site. Even if you don’t use the browser’s built-in password manager regularly, this means you may have some of your credentials saved, whether by choice or by accident.

Before disabling the Firefox password manager, you should first see if you have any credentials saved and, if so, which ones. This will let you know if your stored credentials are up-to-date and whether they need to be deleted altogether. If you use a Firefox account, all changes will apply to the devices you’re logged in on via synchronization.

Keep in mind that disabling the built-in password manager won’t automatically clear your storage—if you ever turn it back on, your old data will be easily accessible. That’s not ideal if you don’t plan to use Firefox for your password storage in the future. To be sure that this information is gone for good, you have to delete all stored credentials manually. For more in-depth information on viewing, editing, and deleting your passwords on Firefox, check out our dedicated guide.

That said, if you find valuable information stored in your Firefox password manager, you might want to preserve it before deleting it from the browser. We recommend exporting your saved credentials from Firefox and storing them in a secure location until you can import them to a different password manager.

To export passwords from Firefox, follow these steps:

  1. Click the three lines in the top right corner of the browser and select “Passwords.”

  2. Tap the three dots on the upper right side of the “Passwords” page to open the menu. Then, click “Export passwords.”

  3. You will be warned that your exported credentials will be saved as a non-encrypted, readable file. Select “Continue with Export.”

  4. Choose your preferred location to store the file and click “Export.”

Keep your exported file safe. If you plan to import the credentials to a different password manager, delete the file immediately afterward.

Turning off the Firefox password manager on your device

You can easily control the Firefox password manager settings on both desktop and mobile devices.

On desktop

To disable the Firefox password manager on a Windows or macOS device:

  1. Click the three lines in the top right corner of the browser and select “Passwords.”

  2. Tap the three dots on the upper right side of the “Passwords” page to open the menu. Here, select “Preferences.”

  3. Toggle off the “Ask to Save Passwords” checkbox.

On mobile

To turn off the Firefox password manager on an Android or iOS device:

  1. Tap the three dots (on Android) or three lines (on iOS) and go to “Settings.”

  2. Select “Passwords.”

  3. Under “Save Passwords,” toggle on “Never Save.”

Changing your password manager from Firefox to a third-party provider

With the Firefox password manager switched off and your exported credentials resting on your device, it’s time to consider where your next password storage will be. It’s not a good idea to keep this data out in the open. If anyone got their hands on your device or if you accidentally shared the file with others, your accounts could be compromised.

So, you should find a solution that offers more protection against password leakage—and yes, setting up a spreadsheet file is also out of the question. Another not-to-do item on this list is changing all your passwords to the same one. It might seem like the simplest solution, especially considering that the average person handles nearly 170 passwords. However, if one account gets compromised, the rest might go down with it. Instead, we need to consider a reliable alternative that lets you add variety to your passwords while keeping them secure.

If you’re simply switching browsers, you may be tempted to use its built-in password manager, if it offers one. However, browser-based password managers pale in comparison to third-party providers like NordPass. While Firefox uses AES-256 encryption to protect sensitive data, NordPass has opted for the more advanced XChaCha20—a faster and more secure alternative. NordPass is also convenient to use as a browser extension—you can even get it for Firefox.

When you switch to NordPass, you’ll get the fundamental features you’ve been familiar with on Firefox, like autofill for your credentials and cross-device synchronization, ensuring all your passwords are up-to-date. But that’s just the start—NordPass offers protection for your email address by letting you set up an email mask. You can also scan your vault to see if any of your credentials are old, weak, or reused.

Manage your accounts with ease without leaving your browser with NordPass.

FAQ

Why should you disable the Firefox password manager?

A browser does not offer sufficient security for sensitive data. For example, if someone were to gain unauthorized access to your browser, they could export and access your passwords and breach your accounts.

What happens after disabling the Firefox password manager?

Once you’ve disabled the Firefox password manager, it will stop prompting you to save or autofill your login credentials. However, your previously saved passwords will still be available if you switch the browser password manager back on. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

Activity Log API, Authopia, Editor’s Choice, and more: catch up with NordPass in Q3 of 2024

In the press 

In recent months, NordPass has made some appearances in the media. In some cases, we shared our knowledge and insights into cybersecurity developments. In others, NordPass was the one under the microscope.

PCMag Editor’s Choice

The team at NordPass always strives to grow and improve, bringing you the best password management experience. That’s why it’s been an honor to be selected as PCMag’s Editor’s Choice and take the top spot as the Best Premium Password Manager for 2024. NordPass’ ease of use, slick design, and additional cybersecurity features like Password Health and Data Breach Scanner were highlighted as some of the standouts of our product.

We’re not resting on our laurels, though. This recognition has only made us more determined to stay on top of the game and bring even more robust security features to our user base.

Discussing passkeys with Andrew Shikiar

Earlier this year, NordPass CEO Jonas Karklys sat down with Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, to discuss all things passwordless. During the talk, they went over the early adoption of passkeys and their growth within the past couple of years, the public perception of this technology, and how it aligns with recent and upcoming compliance regulations.

NordPass has been a proud member of the FIDO Alliance since 2022, so the opportunity to discuss the developments in passwordless technology with the organization’s CEO has only strengthened our team’s understanding of what passkeys have to offer. Karklys went on to share his own insights about passkeys in his article on TechRadar.

Joining forces with Factory Berlin

Partnerships help keep our global community strong. That’s why we’re excited to start our partnership with Factory Berlin. Thanks to this new opportunity, we will be able to connect with up-and-coming startups, innovators, and creators.

Factory Berlin creates a space that helps support startups and grants access to resources and networking opportunities. We look forward to sharing our experiences, trading knowledge, and unlocking brand-new opportunities with this community.

Recent product news

It’s not just about talking the talk — we’re ready to walk the walk, too. These past few months have been very productive for us, with several new NordPass features and releases that we’re very excited about.

Detailed Shared Folders actions for Business

We want to bring efficiency and transparency to your organization’s data security by making our features easy to track and effortless to navigate. That’s why you may have noticed some changes and refinements to the NordPass Activity Log feature.

The Activity Log now displays all actions related to Shared Folders, such as when shared access was granted or revoked, what access level was set, which credentials were moved to or from the folder, and if the folder was renamed at any point. It provides more visibility into password management within your organization and offers insights similar to those of the NordPass Activity Log for your individual credentials.

Authenticator with autofill for Business

NordPass Authenticator allows users to add and store two-factor codes directly in their vaults alongside login credentials using NordPass, making it quick and easy to log in with multi-factor authentication when you are on a tight schedule. From now on, whenever you generate time-based one-time passwords (TOTPs) using NordPass Authenticator, you’ll have them autofilled in the login screen. 

By introducing this new mechanism to our Authenticator, we help you optimize multi-factor logins, bringing a higher security standard to your company account security. It resolves the long-standing problem of multi-factor authentication fatigue caused by using multiple apps and manually inputting security information to log in to an account. With the Authenticator, you don’t need to spend precious time switching apps or ensuring you’ve copied or memorized the right sequence before it refreshes and resets — NordPass handles it for you.

Splunk integration and Activity Log API for Enterprise

Clear and transparent documentation is crucial when a company works toward gaining compliance approvals. To make these management processes smoother, we’re excited to be joining forces with Splunk. This new partnership will allow NordPass customers who use Splunk to get automated activity analysis and generate reports for simpler data visualization.

As part of the optimization of data reports, NordPass now allows Admins to extract the full activity log information with the Activity Logs API. Using the API, organizations can monitor their employees’ actions and investigate company-wide activities for potential risks.

User and Group Provisioning via Okta for Enterprise

NordPass aims to make user and group management simpler without compromising security. If your organization’s provisioning system of choice is Okta, we have great news. You can now easily set up User and Group Provisioning in NordPass using your organization’s Okta account.

By combining Okta with NordPass, you can effectively handle onboarding and offboarding, manage access to resources as well as internal and third-party systems, and adhere to your organization’s cybersecurity policies.

Tweaks and improvements

While bringing new features to our users helps expand our cybersecurity capabilities, we haven’t forgotten what we’ve been working on so far. Consistency is key, and our goal is to continue improving and perfecting every feature that NordPass has to offer. We’re always eager to receive your feedback and work hard to improve your experience with NordPass, whether you’re with us for personal or business needs.

Adding dates to Custom Fields

With Custom Fields, we aim to give you more control and flexibility over how you store your sensitive information. We’re always thinking of new ways to expand Custom Fields to suit our customers’ needs — the most recent being the introduction of Date Fields.

From now on, you can select “Add date” and use the calendar to set it. Add a custom name to your date to know its function, for example, when a credential was created, when an ID document expires, or when an account needs updating. This addition will let you flexibly manage your sensitive data and offer a more convenient way to track time-sensitive information.

Authopia is here

Last but not least, we want to spotlight Authopia — a new tool developed by the team behind NordPass. Authopia lets you easily add a passkey widget to a login form on any website or service, making passwordless logins effortless and more accessible than ever before.

Authopia aims to offer companies a simpler passkey implementation method that requires minimal coding and is completely free, suiting organizations of all sizes and budgets. You can learn more about Authopia’s journey from development to launch from Sorin Manole, Head of Product, R&D at NordPass.

Bottom line

Overall, this has been an eventful quarter for NordPass, and we couldn’t be more proud of everything we’ve achieved. Our work for the year is far from over, though — we’ve still got a lot up our sleeves, and we’re not slowing down. We’re happy to have you with us on this journey so far, and we hope you’ll stay tuned and stay safe with NordPass.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

How to change or reset your PayPal password

How to change your PayPal password

PayPal is a quick and easy way to send and receive money. But since it is usually linked to your credit card, it’s important to change your password regularly and always use a strong one.

Please note that you can’t change the password through the PayPal app — you’ll have to log in through a browser.

Here’s how to change your PayPal password in four easy steps:

  1. Log into your PayPal account and click the little gear icon in the upper right corner.

  2. Click on “Security” in the top banner.

  3. Click “Update” in the “Password” field.

  4. Enter your current and new passwords and click “Change password.” All done!

How to reset your PayPal password

If you forgot your PayPal password, you can reset it through the browser and the PayPal app. For that, you need to:

  1. Go to PayPal, click “Log in,” and select “Forgot password?.”

  2. Enter the email address you linked to your PayPal account and click “Next.”

  3. Select your preferred method for the security check, then click “Next” to proceed.

  4. After completing the security check, create a new password for your PayPal account.

How to change your PayPal security questions

Please note that you can’t change the security questions through the PayPal app — you’ll have to log in through a browser.

Here’s how to change your security questions on PayPal:

  1. Log into your PayPal account and click the little gear icon in the upper right corner.

  2. Click on “Security” in the top banner.

  3. Click “Update” in the “Security questions” field.

  4. Select new security questions and write your answers. Click “Save” and you’re done!

How to set up a passkey for your PayPal account

Passkeys are a new and secure authentication standard introduced by the FIDO Alliance. Think of passkeys as a replacement for passwords that use your fingerprint, face, or a device PIN to sign in to apps and websites across the internet. Designed for supreme security and convenience, passkeys facilitate a seamless login process.

If you are interested in setting up a passkey for your PayPal account, here’s a quick rundown of how to do it:

  • Access your PayPal account using your existing username and passwords.

  • Once you access your account you will see an option “Create a passkey.”

  • Now you will need to authenticate via biometrics.

  • Once you’re authenticated, the passkey will be automatically created, and the next time you log in to your PayPal account, you will not need your username or passwords. The passkey will do the trick.

How to use PayPal safely

Using financial services online is convenient, but it can also be risky — there are many malicious actors lurking on the internet, trying to steal your money. Follow these simple tips to increase your security while making payments online:

Avoid making transactions when connected to public Wi-Fi. Hackers can set up fake hotspots and then monitor your actions online. Using a VPN will encrypt your connection, making it impossible for anyone to see the data you send and receive. You only need to be aware of snoopers looking over your shoulder as you type in your passwords!

Keep the PayPal app up to date. Apps can have vulnerabilities and bugs that are not discovered for months. But once they are brought to light, your account could be in danger. Set up automatic updates on your PayPal app to make sure you have the latest security patch installed.

Be cautious with links and attachments in emails. If you get an alarming email from PayPal claiming that your account is in danger and you must change your password immediately, don’t click any links. Open a new tab, enter the address manually, and check to see if your account is really in danger.

Enable two-factor authentication. Passwords are your first line of defense, but using 2FA will take your account security to another level. You can choose to receive a code via text or use an authenticator app or a security key for your PayPal account’s 2FA.

Set up passkeys. Passkeys are a new, passwordless authentication method that offer a more secure and convenient way to access websites and apps using only your fingerprint, face scan, or a device PIN. Because passkeys leverage public key cryptography, they are resistant to phishing attacks, making them even more secure than most multi-factor authentication methods.

Use a unique and strong password. When you change your password, pick one that is impossible to guess. That means using at least 12 characters that include upper- and lowercase letters, numbers, and special symbols. Need help? Try our password generator.

Keep your PayPal password safe with NordPass. Let’s be frank. All of us have way too many passwords on our hands. Remembering each one — well, that’s just an illusion. But with the NordPass password manager you can have all of your passwords securely stored in a single place, and you can autofill them with just a click. The same goes for passkeys — the NordPass Passkey Holder is designed as a secure storage for all of your passkeys. Tidy mess of online life with NordPass today.

Make using financial services online stress-free with NordPass!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

Five strong password ideas to boost your security

What is a good password? 

You might think that the answer to this question would be very subjective, but that’s far from the case. In simplest terms, a good password is one that’s difficult to crack. The stronger your password is, the better it works to protect your accounts from hackers and other malicious actors. A strong, reliable password can sometimes take millions of years to crack, which means that the hackers are less likely to even try to gain them.

When you’re thinking of good password ideas, you need to keep the following criteria in mind:

  • The password should be at least 12-15 characters long.

  • It should use a combination of letters, numbers, and special characters. Spaces are also allowed.

  • It should not be a common word, product, character, name, or anything you can easily find in a dictionary.

  • It should be a combination that only you know and others could not easily predict. We’ll cover some creative password ideas shortly.

  • Each password should be unique and you shouldn’t reuse them for several accounts. If a password you use on several platforms is cracked, that puts all of your accounts at risk.

What is considered a weak password?

Weak passwords consist of sequential letters or numbers, are fewer than eight characters long, or use common words and phrases. The most popular passwords are well-known by malicious actors and are usually what they try first.

According to NordPass’ annual top 200 most common passwords list, “123456” and “password” are the most commonly used and vulnerable passwords. Another example of a weak password would be using the name of a fictional character like “Superman,” “Batman,” or “Joker.”

Examples of bad passwords

Here are some more examples of weak, easy-to-crack passwords:

  • 123456789

  • abc123

  • qwerty

  • iloveyou

  • hello

  • computer

  • password123

If you’re wondering whether your passwords might be weak links, check out the list of the top 200 most common passwords. You’ll find even more examples, as well as some fun facts about the most common passwords around the world.

 

The most common password-cracking techniques

Brute-force attack

During a brute-force attack, a malicious actor uses software that tries every possible combination to find the right one. An eight-character password consisting of upper- and lowercase letters, numbers, and special characters can be cracked in just two hours. Good passwords will take months or even years to break through, depending on their uniqueness and complexity.

Dictionary attack

While brute-force attacks try various combinations of special characters, numbers, and letters, a dictionary attack uses a program that goes through a prearranged list of words. Essentially, if your password can be found in a dictionary, specialized software can easily crack it.

Phishing

Phishing is a social engineering method to trick people into revealing their credentials. Phishing attacks often use email services as a medium: hackers send emails pretending to be reputable sources and refer users to fake login pages. A user then inputs their login credentials themselves and inadvertently grants this information to the hackers.

Credential stuffing

Credential stuffing is a popular method for hackers to gain access by collecting usernames and passwords used in previous attacks and trying them on other platforms. This method often proves successful because people tend to reuse the same password for all their accounts.

Keylogging

Keylogging involves a specific type of malware, known as keylogger, infecting the victim’s device. The keylogger can then track the user’s keystrokes and device activity, depending on the software and the device. This can include copied and pasted data, phone calls, location, and screenshots. Using this information, hackers can easily access passwords and other sensitive information, allowing them to launch further attacks on the individual or data from their place of work.

How to create a strong password

  • The longer your password is, the better. Many websites ask you to create eight-character passwords, but we recommend going for at least 15 characters.

  • Avoid ties to your personal information, such as your name, surname, address, or date of birth.

  • Use a combination of numbers, symbols, and upper- and lowercase letters in random order.

  • Don’t use sequential letters and numbers.

  • Avoid substitution: “kangaroo” and “k@ng@r00” are both equally weak passwords, and a brute-force attack can easily crack them.

  • Don’t reuse the same password for multiple accounts.

With our free password security tool, you can check your password strength and if it has been exposed in any data breaches. You can also try the Password Health feature with NordPass Premium. It scans all passwords that you’ve saved in your Vault and checks for vulnerabilities.

Top 5 strong password ideas

Coming up with a strong and unique password can be a challenge. To make this process easier for you, we’ve gathered some examples that will help protect your data and accounts from being breached and taken over. We’ve also included some formulas and passphrase examples that you can try yourself. However, we highly recommend you don’t use the example passwords for your accounts.

1. Shorten each word

Think of a phrase and remove the first three letters of each word (in some cases, that might mean deleting full words, but that’s fine):

“Laptop running free in the jungle” -> “top ning e gle”

Sounds like gibberish? That’s exactly what we want. Just don’t forget to add special characters and numbers to make it more complicated. It would take 94,000 years to crack this password.

2. Create your own formula

Create a formula that will help you remember the password. For example, you can take a phrase and replace every letter with the next one in the alphabet:

“Cucumbers are tasty” -> “dvdvncfst bsf ubtuz”

Another clever way of creating strong passwords is to turn song lyrics into acronyms. This means using only the first letter of each line of your favorite song.

So, “Shine on you crazy diamond” by Pink Floyd becomes “rsnsybccystswrcc.”

The time needed to crack this password is 746 million years.

3. Play with the vowels

This one is much easier to implement and memorize: take a random nonsensical phrase and replace one vowel with another (for example, “a” with “e”):

“A car is floating in a pan” -> “e cer is floeting in e pen”

Don’t forget – spaces are allowed in passwords, and we highly encourage you to use them. The combination of having spaces and switching the vowels around means the above password would take 583 million trillion years to crack.

4. Mix the codes of your favorite countries

This one is quite fun and easy to memorize. You will always generate good passwords with this method. Simply make a list of the ISO codes of your favorite countries and put them together:

“Mexico, Ireland, France, Germany, Japan” -> “mex irl fra deu jpn”

You wouldn’t think so, but a hacker would require a staggering six thousand trillion years to crack this password!

If you want to spice things up and make them even more difficult to crack, you can also add each country’s calling code:

“mex54 irl353 fra33 deu49 jpn81”

Such a password would take 12 decillion years years to crack. How impressive is that?

5. Use a password manager

If creating and remembering random phrases for all your accounts seems too complicated, you can use a password manager, such as NordPass. It’s an easy-to-use app that lets you generate strong, unique passwords and securely store them in an encrypted Vault. You can also easily use NordPass to autofill online forms and fields.

You can add as many passwords as you need and access them from any device. This way, you can get the best of both worlds by combining your creative password ideas with one-of-a-kind secure ones created by the password manager for each account without the risk of forgetting them. You can use a special code and get an additional month of NordPass Premium for free when you purchase a two-year plan.

Additional tips

Here are some more tips to keep in mind when you’re looking for good password ideas:

  • In order to protect your data, remember that passwords must be difficult to predict. Including special characters and spaces increases the time it takes for your password to be cracked.

  • Take your phone security into consideration. According to research, pattern locks are successfully replicated around 64% of the time. Instead, set up a PIN or use our guide to generate some strong phone password ideas.

  • Don’t forget to implement new password ideas for work. Don’t reuse your personal passwords because if they ever get breached, your work accounts could be in danger, too.

  • Always use multi-factor authentication (MFA). Even if your password is definitively strong, accidents can happen and your first line of defense might be breached. Using MFA means that no one can access your accounts without accessing your authentication device. NordPass uses multi-factor authentication to add an additional layer of security to your password vault.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.