Security library

Password Security Guides

Practical, people-first guidance for unique passwords, password managers, recovery codes, phishing and breach response.

Topic hubIndependent educational resource

Password security library

Understand password length, reuse, breach response, hashing, recovery and the attacks that turn one exposed credential into many compromised accounts.

How to use this section

Use the Password security library directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.

What belongs in this section

Begin with the issue that creates the largest blast radius: a compromised primary email, reused password or weak recovery path. Concept pages are useful only when they lead to a specific change or monitoring decision.

Brute-Force vs Dictionary Password Attacks

Compare exhaustive guessing, wordlists, rules and online rate limits.

Open guide →

Credential Stuffing Explained

Understand how attackers reuse exposed username-password pairs and how unique credentials stop the chain.

Open guide →

How Long Should a Password Be?

Understand practical password length recommendations, NIST guidance and why length must be combined with uniqueness and randomness.

Open guide →

How to Check for Account Takeover

Review sessions, recovery changes, messages, transactions and connected apps after a suspicious alert.

Open guide →

How to Create a Strong Master Password

Build a unique master passphrase that is long, memorable and protected with multifactor authentication.

Open guide →

Password Hashing vs Encryption

Understand why passwords should be verified with slow hashes rather than stored with reversible encryption.

Open guide →

Password Security Checklist

Audit passwords, recovery methods, multifactor authentication, devices and breach response with a practical checklist.

Open guide →

Password Spraying Explained

Learn how attackers test a few common passwords across many accounts and how organizations can respond.

Open guide →

Password vs Passphrase: Which Is Better?

Compare random passwords and passphrases for password managers, master passwords, Wi-Fi and everyday accounts.

Open guide →

Password Salts and Peppers Explained

Learn how unique salts and separately protected peppers strengthen password-hash storage.

Open guide →

Secrets Management Basics

Protect API keys, tokens, certificates and passwords across creation, storage, use and rotation.

Open guide →

How Secure Password Reset Links Should Work

Understand one-time tokens, expiration, HTTPS and user-notification practices.

Open guide →

What to Do After a Data Breach

Follow a prioritized response plan after a service reports exposed account information or you suspect credential theft.

Open guide →

Why Password Reuse Is Dangerous

Understand credential stuffing, password reuse risk and how to move to unique passwords without losing access.

Open guide →

Standards and source notes

This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.