CYBER WELFARE

Protect your Digital Privacy

Password Generator: Stop Inventing Passwords Yourself

Additional resource for the lesson “Password Generators: Stop Inventing Them Yourself” — Online Security course

Every password you invent carries a fingerprint: a pattern, a preference, a habit you did not notice you had. A password generator has none of those. This resource is about handing over a task you were never well suited to, and getting stronger credentials for less effort.

A. Why this matters

The idea behind this lesson is small and changes a lot: stop inventing passwords. Let a generator — usually built into a password manager — produce them instead.

What follows is that every account ends up with a long, complex, unique credential, without you having to think about any of it. The risk of credential stuffing, where attackers replay passwords stolen elsewhere, drops away, because there is nothing repeated to replay.

The key idea: this is one of the rare security changes that makes life easier rather than harder. The work goes down and the protection goes up at the same time.

B. Key concepts

Six ideas, each with what it means in practice.

Password generator

A tool — inside a password manager, or built into your browser — that creates long, random passwords on demand.

Why it matters to you: It removes weak and ‘creative but predictable’ passwords in one move, and takes seconds rather than the minute you would spend inventing something worse.

Password manager

An application that keeps all your credentials in an encrypted vault, opened with a single master password.

Why it matters to you: It is what makes generated passwords usable at all: you can have a different complex password everywhere without remembering any of them.

Uniqueness, meaning no reuse

Every account gets its own password, with nothing shared between them.

Why it matters to you: If one site is compromised, attackers cannot use what they found there to reach your email, your bank or your work accounts.

Length and complexity

At least 15 or 16 characters, mixing letters, numbers and symbols. Recent guidance puts increasing weight on the length.

Why it matters to you: More unpredictability means far more time and computing power needed to break it — which usually means it is never seriously attempted.

Credential stuffing

Attackers taking credentials exposed in one breach and trying them automatically across many services.

Why it matters to you: This is the concrete answer to ‘why do I need a different password everywhere?’. Not because each one might be guessed, but because one of them will eventually leak.

Sensible rotation

Current guidance says change a password when there is a reason — a suspected breach, an exposure — rather than on a monthly calendar.

Why it matters to you: Forced routine changes push people towards small predictable edits. Changing when it matters produces better passwords and less fatigue.

C. A practical example: three passwords that were really one

Nadia has used a familiar pattern for years:

  • Email: NadiaRome2020!
  • Social: NadiaRome2021!
  • Online shop: NadiaRome2022!

They feel different to her. To an automated system they are the same password with a counter on the end.

The shop is breached and her credentials circulate. An attacker does not need to guess anything: the same combination, and its obvious variations, are tried across common services. Her mailbox opens. From there, password resets for other accounts arrive in an inbox that is no longer hers, along with the verification codes.

After the lesson

  • She installs a password manager on her computer and her phone.
  • She uses the built-in generator for each account, producing credentials she has never seen and would not be able to repeat.
  • She turns on multi-factor authentication for her email and her bank.
  • From then on, every new account starts with the generate button rather than with her imagination.

The next time a site she uses is breached — and eventually one will be — the exposure stops at that site.

D. Try it yourself: the three-account check

Five to ten minutes. Do not write your real passwords anywhere during this exercise.

Step 1 — Assess, in your head

  • Think of three important accounts: primary email, bank, main social account.
  • For each: is the password reused anywhere? Is it 15 or 16 characters? Does it mix cases, numbers and symbols?

Step 2 — Watch a generator work

  • Open a password manager, or your browser’s built-in generator.
  • Set the length to at least 16 and turn on every character type.
  • Generate a few. Notice that none of them look like anything you would have produced.

Step 3 — Commit to one account

  • I will set a generated password for one critical account.
  • I will store it in a password manager.
  • I will turn on the second factor for the same account.

This works well as something to finish after the lesson rather than during it. One account, done properly, is worth more than a plan for all of them.

E. Videos, articles and further resources

Independent and institutional sources in English.

CISA — Use strong passwords
The US agency’s guidance for the public, which names using a password manager as one of four basic actions.
https://www.cisa.gov/secure-our-world/use-strong-passwords

NCSC (UK) — Password managers: how they help you secure passwords
A sober answer to the question most people ask first: is it safe to keep all my passwords in one place?
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers

NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
Where the current advice comes from, including the shift away from routine password expiry.
https://pages.nist.gov/800-63-4/sp800-63b.html

EFF — Creating strong passwords
A clear method for building a passphrase you can actually remember, including the dice-based approach.
https://ssd.eff.org/module/creating-strong-passwords

NCSC (UK) — Using password managers and passkeys to stay secure online
How today’s tools reduce password fatigue instead of adding to it.
https://www.ncsc.gov.uk/blog-post/trust-the-tech-using-password-managers-passkeys-to-help-you-stay-secure-online

Google — Create a strong password and a more secure account
Practical instructions for one of the accounts most people cannot afford to lose. Useful if a Google account is the hub of your digital life.
https://support.google.com/accounts/answer/32040?hl=en

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Secure Behavior pillar at level FL2: the knowledge is simple, and the change is a habit.

Skills

  • Using a generator, whether in a password manager or a browser.
  • Setting up a password manager properly: strong master password, backup, access from more than one device.
  • Understanding how length and uniqueness relate to what attacks can actually do.

For professionals and organizations

  • Configuring the generator defaults centrally, so the right choice is the automatic one.

Awareness

  • Recognising reuse as the specific habit that credential stuffing depends on.
  • Understanding that a pleasing password is usually a predictable one.
  • Connecting credential quality to identity, personal data and work information.

For future instructors and ambassadors

  • Presenting the generator as the thing that removes work, not adds it. That framing is what makes people try it.

Secure Behavior

  • Generating a password every time a new account is created, without exception.
  • Securing the critical accounts first: email, work, bank, digital identity.
  • Keeping the password manager and its devices up to date.

For organizations

  • Dropping calendar-based password expiry, which pushes people towards predictable edits (see R6 and current guidance).

G. Questions to sit with

  1. How many of your important accounts still use a password you invented from memory?
  2. If one of the services you use were breached today, how many other accounts would go with it?
  3. What is holding you back from a password manager — trust, habit, or the sense that it will be complicated? Which of those is actually true?
  4. Which account will you secure with a generated password and a second factor in the next 24 hours?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply here.

Credentials

  • R1 — Do not use the same, or nearly the same, password across your accounts.
  • R2 — Use a reliable password manager with a unique master password.
  • R3 — Bring your most important passwords — email, bank, work — to at least 16 characters with numbers, upper and lower case letters and symbols.
  • R4 — Turn on multi-factor authentication for critical accounts: email, bank, digital identity.
  • MS1 — Use the generator, usually built into the manager, for every account.
  • MS2 — Use autofill rather than typing passwords by hand: fewer errors, less reuse, less exposure to fake pages.

Around the credentials

  • R6 — Keep your software up to date, including the password manager itself, with automatic updates on where possible.
  • MS17 — Give the email address linked to your bank accounts particular attention: unique, generated password plus a second factor, preferably an authenticator app or hardware key.

Four steps, in order

  1. Choose a password manager.
  2. Generate new, unique passwords for one to three critical accounts.
  3. Turn on multi-factor authentication for them.
  4. From here on, every new account starts with the generate button.

After that last step there is nothing left to maintain. You stop inventing passwords and start simply keeping them safe.

In short

  • Invented passwords carry patterns; generated ones do not.
  • Reuse is what credential stuffing needs — and a generator makes reuse impossible by default.
  • Change a password when there is a reason, not on a calendar.
  • This is the rare change where less effort produces more protection.

Related resources in this course

The tools and the reasoning behind them:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program