A password audit in one evening

Practice

Forty accounts cannot be fixed at once. Sort them by importance: what to change today, what this week and what to leave alone.

The advice “make every password unique” sounds reasonable right up to the moment you open the saved list in your browser and find seventy entries. Nobody gets through that in one sitting, which is exactly why most people never start.

The good news: you do not have to. Out of seventy accounts, five to seven are critical, and one evening is enough to close them properly.

Step by step

  1. Collect the list

    Open the saved passwords in your browser and export them to a file. Everything you forgot will be there: forums from ten years ago, shops with a single order, services that already shut down.

    This is the unpleasant part — the list will be longer than you expected. Everything after it gets easier.

  2. Sort into three buckets

    Not alphabetically and not by date, but by one question: what happens if this account is stolen? The answer sets the priorities immediately, and the table below shows how.

  3. Install a password manager

    Without one, unique passwords are physically unachievable. Import the exported file and then delete it — it sits unencrypted in your downloads folder.

    Which one to pick and how cloud differs from local is covered in the article on password managers.

  4. Check what already leaked

    Run the first bucket through the breach check. Change any matches immediately and first — they sit in the lists every attack starts from.

  5. Fix the first bucket

    Five to seven accounts, three minutes each: a new sixteen-character password, a second factor, a check of the recovery contacts. That is the evening.

  6. The rest as you go

    Do not sit down to change sixty passwords in a row: you will quit at the fifteenth. Change one at a time when you are logging in anyway. Within a year the list runs out by itself.

How to sort the buckets

BucketWhat goes thereWhat to do
TodayEmail, banking, government services, the password manager, work systems, shops with a saved cardA unique password of 16+ characters and a mandatory second factor
This weekSocial media, messengers, cloud storage, food delivery, subscriptionsA unique password, a second factor where offered
SomedayForums, one-off sign-ups, services with no personal data and no paymentsChange at the next login, not before
The test for the first bucket is simple: through this account someone can recover access to others or spend money.

What changes after the audit

Before
  • One password with variations everywhere
  • A breach of any forum opens your email
  • Passwords live in a browser on one computer
  • Login by password only
  • No idea what to change when a breach is announced
After
  • A unique password per service
  • A forum breach stays a forum breach
  • Passwords available from any device
  • Critical accounts covered by a second factor
  • There is a list: you can see what is affected

Three mistakes that end audits early

  • Trying to do it all at once. Seventy accounts is eight hours of monotony. The first bucket takes forty minutes and delivers ninety per cent of the result.
  • Changing the password without changing the scheme. “Summer2026!” to “Autumn2026!” is not a new password. Cracking rules try such variations first.
  • Forgetting the recovery contacts. A new password will not help if the account is tied to a phone number you stopped using five years ago.

If one of the passwords turns out to be already exposed, follow the instructions in what to do if your password leaked: the order of steps matters there.

Copied