Skip to main content

Password security tips you were overlooking

Here’s our guide to creating secure passwords you can actually remember (and no one else can guess!).

August 27, 2026
Aline Rivas, Head of Content & Social Media

Password security has come a long way since writing it down on a Post-it note and putting it on a fridge. These days, it looks like a three-step dance: Notes app, reset password and repeat. And yet? We’re all still doing it.

Somewhere between your streaming service, online banking, work email and all the different online stores you’ve created accounts on, you’re probably using some version or variation of the same password. That’s risky. It’s a disaster waiting to happen. These passwords are like dominoes. One falls, and the rest follow.

The good news is that password best practices don’t require memorising 47 different strings of random characters. It just needs a few good habits and one good tool…

Here’s our guide to creating secure passwords you can actually remember (and no one else can guess!).

TL;DR

  • A long passphrase like Horse-Battery-Staple-Correct can actually have better password security than P@55w0rd… plus it is much easier to remember.

  • Reusing passwords across sites is the single biggest security risk most people take without realising it.

  • A good password manager means you only need to remember one password. Everything else gets handled.

  • Check HaveIBeenPwned.com to find out if your email has appeared in a password data breach.

Length beats complexity

There's this myth that a "strong" password looks like &!pR8B>5.F$h%TCf.

Undoubtedly, that is a hard one to crack. But it’s also too hard for someone to remember…at which point they give up and use something weaker.

Length comes out on top when considering password security. A phrase like onion-gingerbread-castle-mirror looks random and unrelated to others, but it could mean something to you…like a tribute to your favourite cantankerous ogre.

That’s why it’s harder for a computer to crack…but it’s super easy for you to actually remember.

What’s a paraphrase password and why is it better for security?

The sweet spot for most people is a passphrase. It’s easy to remember even if you have a goldfish memory, while being really secure.

What are some tips on creating a paraphrase password?

  • The longer the better – Aim for a password of four or more random words. At least 15 characters if possible. For your most important account, you need a password that is at least 16+ characters.

  • Unpredictable phrases – Don’t use a sentence; instead, you’ll want a random jumble of unrelated words. There are tools available to help, or you could just open a book at random.

  • Unique phrases for important accounts – Make sure your email, online banking and financial accounts have different passwords. You could even try adding a modifier for each one based on the platform. For example, ‘pizza bottle witch apple email’ or ‘insta pizza bottle witch apple’.

It is a sin to reuse passwords!

Reusing passwords feels like your life is easier. It is, in fact, the security equivalent of using the same key for your front door, your car and your office.

You’ve basically handed a copy to every single website you’ve ever signed up for, as well.

Here's how credential stuffing works:

  • A company you have an account with gets breached (this happens constantly, often to companies you'd never expect).

  • Your email and password are dumped into a database and sold.

  • Automated tools try that exact combination on hundreds of other sites within minutes. Yes, that includes your banking, email and social media.

  • If you've reused that password anywhere, those accounts are now compromised, too.

This is the most common way accounts get taken over. And the only fix is unique passwords for every account. For most people with dozens or hundreds of accounts, it means a password manager.

Password managers: The one tool that’s worth it

A password manager stores all your passwords in an encrypted vault, generates new strong ones when you need them and fills them in automatically.

Remember this password, and the manager will handle everything else.

Recommended options:

Tool

Cost

Best for

1Password

Approx. $5/month

Best overall experience, great for families

Bitwarden

Free (premium $3/month)

Best free option, open source

LastPass

Free / paid tiers

Widely used, cross-device sync

Apple Passwords

Free (built-in)

iPhone/Mac users who stay in the Apple ecosystem

Google Password Manager

Free (built-in)

Android/Chrome users

Tool descriptions, features, and pricing are based on information available at the time of publication and may be subject to change.

Getting started is simpler than it sounds:

  1. Download the app and browser extension

  2. Create your master password (make it a strong passphrase — this is the one you'll actually need to remember)

  3. As you log into sites normally, your manager captures and saves each password

  4. Over time, change old reused passwords to unique generated ones. Prioritise email, banking and social media first

Check if you’ve already been breached

Go to HaveIBeenPwned.com and enter your email address. You might have heard about it before, but it’s something you should be regularly checking up on.

What is HaveIBeenPwned?

It’s a website made by security researcher Troy Hunt that tells you exactly what security breaches your email appeared in by cross-checking it with known data. It also tells you what type of data has been exposed.

What should I do if my email appears:

  1. Obviously, you’ll need to change your password for the breached account.

  2. Change your password everywhere else you’ve reused this password.

  3. Enable two-factor authentication (2FA) on these accounts.

  4. Set a reminder to check HaveIBeenPwned again after you hear of any major breaches.

Two-factor authentication: The extra lock

Even a perfect password can be compromised by a keylogger, a phishing attack or someone physically watching you type.

Two-factor authentication (2FA) means that even with your password, an attacker still can't get in without a code from an app on your phone.

Enable it on:

  • Your email account (this is the most important one since email is the recovery route for everything else)

  • Your banking and financial accounts

  • Your password manager itself

  • Social media accounts

An authenticator app (Google Authenticator, Twilio Authy) is more secure than SMS codes, which can be intercepted. But SMS 2FA is still much better than no 2FA at all.

How often should you update passwords?

The whole "change your password every 90 days" doesn’t really apply anymore. Don’t force yourself to come up with new phrases, you might actually end up choosing weaker passwords.

Here are some better tips for password protection:

  • Change immediately when a breach occurs or HaveIBeenPwned flags your email

  • Change annually for high-value accounts (email, banking) as a general habit

  • Change whenever a service you use announces a data breach, even if you're not sure you were affected

  • Change your Wi-Fi password at least once a year, or whenever a former household member or regular guest moves on

Protect your whole network with eero Secure

What about everything in your network that you can’t see? eero Secure is the security layer that works in the background, catching malicious websites, links and suspicious traffic before they reach your precious devices.

Not just the laptop too…it protects your phone, the smart TV, the tablet...you name it.

What eero Secure does:

  • Blocks phishing sites and malicious links in real time — the ones designed to look exactly like your bank or your email provider

  • Network-wide ad blocking — no extensions, no per-device setup, just off at the source

  • Content filters — by age, category, social media, streaming and gaming platforms

  • Usage insights — see what's actually happening on your network, by device

  • Site block and allow lists — custom rules for specific devices or users

See what else is included with eero Secure, or discover more about the eero 7 or the eero PRO 7.

Online safer with Superloop

Good security habits protect your accounts. And a reliable, secure connection protects your data in transit. Stay safe online with Superloop and explore our nbn® plans today.

FAQs

Generally yes. Browser-based password managers from Google and Apple are encrypted and reasonably secure. Just make sure your device account itself has strong password security.

At least once a year. Change it immediately if you think someone’s accessed it without your permission, if one of your housemates has moved out of the sharehouse or if you’re in a small office and someone’s left.

Sometimes it will give you a hint, but at the very least, it should have 15 characters, mixing upper and lower case letters, numbers and symbols. Length is the most important factor. A short, complicated password is usually weaker than a long, simple one.

No. Passwords are encrypted. Superloop cannot view your password, and no legitimate company can. Anyone claiming to be from Superloop and asking for your password is not from Superloop.

If you need to reset your password, that's done through the official account portal and not via email.

Written by

Aline Rivas
Head of Content & Social Media

I've spent the last 4 years at Superloop making complex telco topics genuinely easy to read, driven by a mission to help challenger telcos take on the big guys.

Related articles

We’ll walk through common smart home troubleshooting steps, share smart home tips and help you figure out whether the problem is your Wi-Fi, your device or something else entirely.

October 13, 2025

Explore the critical aspects of recognising when an upgrade is necessary, selecting a new plan and making the switch to ensure an optimal home internet experience.

April 26, 2024

If we accept that learning is all about interaction and making connections, then education and digital communications could hardly be a better fit. And now, more so than ever.

June 22, 2020

Refresh your internet

Type to show suggested addresses. Use the up and down arrow keys to move through the list, Enter to select an address, and Escape to close the listbox.