LThe Life Starter
0 of 6 complete0%
Lesson 2 of 6
Digital · Guided lesson

Move to unique passwords

Stop one breached password from unlocking multiple accounts.

About 25 minutes Finish with a concrete deliverable
Cybersecurity and Infrastructure Security AgencySecure Our WorldYouTube
Course primer

Secure Our World

From Cybersecurity and Infrastructure Security Agency. Watch here or open it on YouTube .

When CISA recommends strong passwords and a manager, perform the change on one critical account while confirming the new login before deleting old access.
Before you begin

What this lesson is really solving.

Let a password manager generate and store long, unique passwords. Protect the manager itself with a strong unique master password and best available MFA. Change reused credentials beginning with critical accounts and known breaches.

Why this works

Understand the idea before touching the steps.

A password manager is a key ring: one protected vault lets every door use a different strong key.

Do this

Follow these steps in order.

Take the action in each step; then use the deliverable below to prove the lesson is finished.

  1. 1

    Choose a reputable password manager and protect it with a long, unique master passphrase.

  2. 2

    Import or add accounts, then change reused passwords starting with the critical-account map.

  3. 3

    Let the manager generate long random passwords and save the new credential before closing the reset flow.

  4. 4

    Store the recovery kit securely offline and never place the master password inside the unlocked vault alone.

Worked example

See the standard in context.

Sam imports a browser list, removes duplicates carefully, changes primary email and financial passwords to generated values, and records only recovery codes—not passwords—on an offline emergency sheet. Reuse falls from 31 accounts to zero over two sessions.

Quality check

Inspect before you move on.

  • Critical passwords are long, random, and unique.
  • The password-manager master credential is not reused or casually stored.
  • Emergency access is documented without creating an exposed plain-text password list.
Make it real

Your deliverable

A password vault with unique credentials for every critical account and a secure recovery kit.

Common mistake

Watch for this

Changing many passwords quickly without confirming that each new credential and recovery method works.

You’re ready when

Prove it—don’t just recognize it.

No two critical accounts share a password and you can recover the vault if a device disappears.

Objective evidence · 3 questions

Quick knowledge check

Answer from the lesson—not from confidence alone. Score at least 2 of 3 to unlock completion.

Not yet passed

This curriculum-aligned check is scored automatically and stored with your account when signed in. It is an objective learning signal, but it has not yet been independently validated as a standardized assessment.

1Which action belongs in the recommended process for “Move to unique passwords”?
2Which result is the clearest evidence that this lesson’s work is complete?
3Which choice matches the failure this lesson specifically warns against?
0 of 3 answeredEach question measures the action, evidence, or failure condition taught above.
Useful for this course

Tools, templates, and references

The Life Starter toolkitReusable planners and trackers for practical projects.
Check current detailsReferences reviewed September 9, 2026. Lesson exercises are editorial synthesis; official rules come from the linked sources.
CISA — Secure Our WorldNIST — Small business cybersecurity
2
One check remains

Pass the knowledge check above first.

Completion unlocks after a score of 2 out of 3. Then confirm that you produced the lesson deliverable.

Go to the knowledge check