2.4: The Migration
The Migration
You have a manager and one password in it. The obvious next thought — “now I change all fifty accounts” — is the thought that kills the project. Nobody finishes that Saturday. So don’t try. Migrate at two speeds instead.
Today: the high-value list, nothing else
Get out the list from Lesson 1.4: email, phone carrier, bank, cloud backup, the saved-card accounts. Five to eight logins. For each one:
- Log in to the account.
- Go to its password-change setting.
- When the “new password” box appears, let the manager generate one — long, random, ugly. You’ll never type it, so it costs you nothing.
- Save. The manager captures the new password automatically (approve the prompt if it asks).
Start with your primary email, since the master key gets the strongest lock first, then work down the list. Half an hour covers all of them. And it’s worth appreciating what you’ll have done by the end: credential stuffing can no longer reach anything that matters to you. Whatever leaked in whatever old breach, it no longer opens these doors.
Every day after: opportunistic migration
The other forty-some accounts migrate themselves. The rule is simple: every time you log in anywhere, let the manager work. It captures the existing password as you type it. The next time you’re in that account’s settings, or the next time the site forces a reset anyway, you upgrade to a generated one. No appointments, no marathon session. After a month or two of ordinary life, most of your accounts have quietly moved in.
Your manager keeps score for you, too. 1Password calls it Watchtower; Bitwarden has vault health reports; Apple and Google flag reused and compromised passwords. Open that report once a week and watch the reused-password count shrink. It’s a to-do list that only gets shorter, and the day it hits zero feels better than it has any right to.
Practice the save-and-fill habit
Here’s the loop on the practice computer — saving a login, filling it next visit, and the one moment autofill goes quiet on purpose.
While you’re in there: fix the security questions
Whenever you’re inside an account’s settings, spend an extra ninety seconds on its security questions. Consider what “What street did you grow up on?” really is: a password that never rotates, that your relatives also know, and that may be sitting on your Facebook profile or in a data broker’s file. Genealogy sites will answer “mother’s maiden name” for anyone with ten dollars.
The fix is to stop telling the truth. Answer with a deliberate lie — random words from your generator work perfectly (“First street?” → velvet-canyon-lamp) — and store the lie in the manager’s notes field for that login. The question becomes a second random password instead of a public fact. No rule says you have to be honest with a form, and the arithmetic says honest answers are guessable.
The friction you should expect
Some sites will fight you, and it’s better to know that going in. Banks that cap passwords at 12 characters or ban symbols: take the best password the rules allow — it’s still unique, which is the property that matters most. Forms that block pasting: the extension usually fills anyway, and for the worst offenders you can type the generated password once from your phone screen. Airlines with four-digit PINs: generate a random PIN and store it. None of this changes the outcome. Every account ends up with the strongest unique credential it will accept, stored where you’ll never lose it.
Which leaves one question: those old passwords you just retired — how bad were they? Next lesson, you find out with real data.