Module 2: Passwords, Done Once, Properly

45 minutes

Module 2: Passwords, Done Once, Properly

Module 1 established the threat: machines replaying leaked passwords at scale, with reuse as the thing that puts you on their lists. This module is where that risk goes away for good.

When every account has its own long, random password that has never existed anywhere else, credential stuffing has nothing to work with. A breach at one site opens exactly one door, and you can re-lock that door in minutes. A normal person can reach that state in a weekend, and it’s the single biggest security upgrade available at any price — including all the prices above free.

The catch, of course, is that nobody can memorize fifty random passwords. That isn’t a character flaw; it’s arithmetic. So this module also sets up the tool that makes uniqueness effortless, and explains exactly what that tool does with your secrets before asking you to trust it.

Five lessons, two of them hands-on labs:

  • What Makes a Password Strong — entropy in plain words, plus a live lab where you watch crack times change as you type
  • What a Password Manager Actually Is — the vault, zero-knowledge encryption, and a fair comparison of your options
  • Set Yours Up for Real — installation, the master passphrase, and autofill as a phishing detector
  • The Migration — your high-value accounts first, then everything else on autopilot
  • Check the Damage — test your old password patterns against 600 million leaked ones, safely, right on the page

What you’ll walk away with

  • A password manager installed, configured, and holding your high-value accounts
  • A master passphrase you created correctly and can remember
  • Security questions that are no longer a backdoor
  • First-hand proof of whether your old standby password is on the lists

Time

About 45 minutes of lessons, plus the setup work in 2.3 and 2.4 — budget a relaxed hour for those. The rest of the course stands on this module, so give it the time.