Back to BlogSecurity

Password Management and Creating Strong Passwords

by qadminExpertise: Security ExpertPublished on: July 20, 20265 min read
Password Management and Creating Strong Passwords

Passwords are the key to your digital life. Yet most users choose weak passwords and reuse the same password across multiple accounts. This guide explains the basic ways to create strong passwords and manage your passwords securely.

Strong password criteria: at least 12 characters long, with uppercase and lowercase letters, numbers, and special characters. Avoid dictionary words, names, birth dates, and sequences like '123456'. Random passphrases are more secure: for example, 'Blue-Cat-Mountain-42!' as four words combined.

Password manager usage: a password manager (Bitwarden, 1Password, KeePass) stores all your passwords in a secure 'vault'. It generates unique, random passwords for each account. You only need to remember one master password. Bitwarden is open source and audited — important for trustworthiness.

Two-factor authentication (2FA): protects your account even if your password is compromised. Instead of SMS-based 2FA, use app-based (TOTP) or hardware key (YubiKey). SMS is vulnerable to SIM swap attacks. Apps like Google Authenticator, Authy, or the open-source Aegis are more secure.

Password reset: update your account recovery options — recovery email and phone number should be under your control. Make security questions strong and unpredictable (for example, 'Your birth city' with a random answer like 'Purple Elephant' and store it in your password manager).

Common mistakes: using the same password across multiple accounts (if one account is breached, all your accounts are at risk), storing passwords in email or note apps, and using the 'remember password' feature everywhere. These mistakes seriously weaken your account security.

QMOBILE BASEL connection: QMOBILE, with its BASEL-based privacy approach, recommends password managers that comply with Swiss privacy standards. Bitwarden and Proton Pass are open-source options that comply with Swiss privacy laws. QMOBILE Pixel devices work seamlessly with these tools.

Practical steps: first choose a password manager and make your master password strong. Change all your existing account passwords to unique, random passwords. Enable 2FA on all accounts. Regularly check your accounts for suspicious activity. Use the 'Have I Been Pwned' site to check whether your email addresses have been involved in data breaches.

Advanced: use a hardware key (YubiKey) — this is the highest security level. For accounts with FIDO2/WebAuthn support, the hardware key provides complete protection against phishing attacks. Keep multiple hardware keys (primary and backup) and store them in secure places. This is ideal for your most critical accounts (email, banking).

Cookies & Terms of Use

By using this site, you agree to our cookie policy and terms of use.