Skip to content
Utah Community Learning

Finding your reused and weak passwords

About 18 minutes

Finding Your Reused and Weak Passwords

Okay so. Your passwords are in the app now, two-factor is set up on the important stuff, and I bet part of you is thinking we're basically done here.

We're not. Not quite. Here's the thing though... having your passwords IN the app doesn't mean they're good passwords. It just means they're organized. You can have twenty accounts all beautifully saved in your password manager and eighteen of them are the same password you've been using since 2014, with maybe a "!" added on when a website got fussy about it.

That's what we're fixing today. We're going to find the weak spots.

Why this matters (the short version)

If you reuse a password, and one site gets hacked, the bad guys don't just get into that one site. They try that same email-and-password combo on a bunch of other sites automatically, in bulk, in about four seconds. It's called "credential stuffing" and it's not personal, it's just efficient crime. So one leaked password can turn into five compromised accounts real fast.

I'm not a security expert, I want to be clear about that, that's above my paygrade. But this part I know cold: reused passwords are the number one way regular folks get into trouble online. Not clever hackers guessing your dog's name. Reuse.

Let your password manager do the finding

Good news, you don't have to go hunting for this by memory. Your password manager already has a tool built in for exactly this. It's usually called something like "Security" or "Watchtower" or "Password Health," depending which one you picked. Go find it now.

  1. Open your password manager.
  2. Look in the sidebar or settings for something with the word "security" or "health" in it.
  3. Click it. Let it load. It'll take a second, it's checking every password you've got saved against every other one.

You're going to see three kinds of problems show up:

  • Reused passwords — same password, multiple sites.
  • Weak passwords — short, simple, easy-to-guess ones.
  • Old passwords — ones you haven't changed in years. Not automatically bad, but worth a look.

Does that make sense so far... it's basically a report card, and almost nobody gets straight A's the first time. I didn't either.

Don't panic at the number

If it says you've got 34 problems, don't close the laptop. That number is completely normal, and honestly the whole point of pulling this list together is so you're not just carrying that dread around in your head anymore. It's on a screen now, it's a list, and lists are things you can work through one at a time.

Which is a good moment to bring up an opinion of mine: the best system is the one you'll actually keep, not the pretty one. You are not going to fix 34 passwords tonight. You're not going to fix them this week. If you try to, you'll burn out on Tuesday and never open the app again. So we're not doing that.

Pick the worst five, not all of them

Here's how I actually do this, and how I want you to do it tonight:

  1. Sort the list, if you can, by "most reused" or "most important" — some apps will flag banking and email accounts specially, which is smart, use that.
  2. Pick your top five. Priority order: banking, email, anything with your social security number attached, then everything else.
  3. For each of those five, click "change password" right in the app if it offers that. A lot of them will even take you straight to the site.
  4. Let the app generate a new, random password for you. Don't write your own. That's the whole reason we're doing this.

And this next part matters more than anything else in this lesson, so I'm going to slow way down for it.

Save the new password in the app FIRST. Then change it on the actual website.

I learned this one the hard way, and I mean the hard way. I was feeling real proud of myself, real organized, changing a password on an account, and I changed it on the website before I'd saved the new one anywhere. Closed the tab. Went to log back in five minutes later and had... nothing. Not the old password, because I'd already changed it. Not the new one, because I never wrote it down anywhere real. Forty minutes and a password reset later I was back in, feeling not very organized at all.

So: save first, then change. Every time. It feels backwards but it's not.

The folder system all over again

This is basically the same lesson as version two of my file folders, if you remember that story — my first system made total sense to me at eleven at night and meant nothing to me the next morning. Same idea here. A password that feels clever when you make it up is worthless if you can't reproduce the logic later. Let the machine generate it. Let the machine remember it. That's the whole deal.

A word of caution

Don't do this at 11 p.m. after a long day, when you're tired and clicking fast. Changing passwords is one of those tasks where a slow, boring pace is actually the safe pace. If you get logged out somewhere unexpectedly, don't panic and start clicking around, just close it and come back to it when you can pay attention.

Before next time

Pick your top five weak-or-reused passwords from tonight's security check and get them changed, using save-first-then-change. Five is plenty. We'll keep chipping at the rest as we go. 👍