Getting started is simpler than it sounds:
Download the app and browser extension
Create your master password (make it a strong passphrase — this is the one you'll actually need to remember)
As you log into sites normally, your manager captures and saves each password
Over time, change old reused passwords to unique generated ones. Prioritise email, banking and social media first
Check if you’ve already been breached
Go to HaveIBeenPwned.com and enter your email address. You might have heard about it before, but it’s something you should be regularly checking up on.
What is HaveIBeenPwned?
It’s a website made by security researcher Troy Hunt that tells you exactly what security breaches your email appeared in by cross-checking it with known data. It also tells you what type of data has been exposed.
What should I do if my email appears:
Obviously, you’ll need to change your password for the breached account.
Change your password everywhere else you’ve reused this password.
Enable two-factor authentication (2FA) on these accounts.
Set a reminder to check HaveIBeenPwned again after you hear of any major breaches.
Two-factor authentication: The extra lock
Even a perfect password can be compromised by a keylogger, a phishing attack or someone physically watching you type.
Two-factor authentication (2FA) means that even with your password, an attacker still can't get in without a code from an app on your phone.
Enable it on:
Your email account (this is the most important one since email is the recovery route for everything else)
Your banking and financial accounts
Your password manager itself
Social media accounts
An authenticator app (Google Authenticator, Twilio Authy) is more secure than SMS codes, which can be intercepted. But SMS 2FA is still much better than no 2FA at all.
How often should you update passwords?
The whole "change your password every 90 days" doesn’t really apply anymore. Don’t force yourself to come up with new phrases, you might actually end up choosing weaker passwords.
Here are some better tips for password protection:
Change immediately when a breach occurs or HaveIBeenPwned flags your email
Change annually for high-value accounts (email, banking) as a general habit
Change whenever a service you use announces a data breach, even if you're not sure you were affected
Change your Wi-Fi password at least once a year, or whenever a former household member or regular guest moves on
Protect your whole network with eero Secure
What about everything in your network that you can’t see? eero Secure is the security layer that works in the background, catching malicious websites, links and suspicious traffic before they reach your precious devices.
Not just the laptop too…it protects your phone, the smart TV, the tablet...you name it.
What eero Secure does:
Blocks phishing sites and malicious links in real time — the ones designed to look exactly like your bank or your email provider
Network-wide ad blocking — no extensions, no per-device setup, just off at the source
Content filters — by age, category, social media, streaming and gaming platforms
Usage insights — see what's actually happening on your network, by device
Site block and allow lists — custom rules for specific devices or users
See what else is included with eero Secure, or discover more about the eero 7 or the eero PRO 7.
Online safer with Superloop
Good security habits protect your accounts. And a reliable, secure connection protects your data in transit. Stay safe online with Superloop and explore our nbn® plans today.