Security
Passwords & Home Online Security: The 2026 Guide
Passwords and home online security: the short answer
No password is a guarantee on its own. But the order of protection is clear: a long, unique password for every service, ideally from a password manager, plus two-factor authentication or a passkey for all important accounts. For the home network you add a strong, unique Wi-Fi password, WPA2 or WPA3 and a separate guest network. Doing these basics covers the most common attack paths: guessed or reused passwords, data breaches, phishing and insecure Wi-Fi.
The Password Generator creates a random, unique password for each account, and the Password Checker tells you whether a password pattern is already known and too weak. Our Security Setup playbook walks you through setting up your most important accounts and devices step by step.

Why a password alone is not enough
A password is only a single knowledge factor. If it is guessed, reused, captured through phishing or taken from a data breach, it opens access immediately. Attackers use very different techniques, and the right defence depends on the type of attack.
| Technique | What happens | What helps |
|---|---|---|
| Brute force | A program systematically tries combinations of characters. | Length, rate limits, two-factor authentication, passkeys |
| Dictionary attack | Common words, names and keyboard patterns are guessed. | Do not use dictionary words or personal details on their own |
| Rule-based attack | Known words are varied by patterns, such as a capital first letter, a digit at the end. | No predictable replacements, better random passwords or passphrases |
| Credential stuffing | Stolen email and password combinations are tried automatically on other services. | A unique password per service, 2FA or passkey |
| Phishing and infostealers | Credentials are captured on fake pages or stolen directly from a device. | Check the URL, use a passkey, protect the device, revoke sessions |
With an online login, the service can limit or delay login attempts. With an offline attack, the attacker instead holds a stolen password database and can attack the hashes at leisure. How well you are protected then depends on how the service stored the password. A service should never keep passwords in plain text, but should derive a hash with an adaptive method. MD5 and SHA-1 are unsuitable because they compute too fast. bcrypt is still common, and Argon2id is the recommended modern choice, both deliberately slow and memory-intensive (as of 2026).
A salt is a random per-password value mixed in during hashing. It ensures that the same password produces different hash values for two accounts and makes precomputed rainbow tables useless. It does not, however, make a weak password strong.
The most important lesson for everyday life: length beats a predictable complexity pattern. More independent random characters enlarge the search space more than forced special characters that many people place in the same way. What counts is unique, random passwords that are new for every service.
What really makes a strong password in 2026
The recommendations of the authorities are now surprisingly aligned, even if they are worded differently. The BSI and the Verbraucherzentrale give two paths: a shorter, complex password with at least 8, ideally 12 characters and four character types, or a longer one with at least 25 characters and at least two character types. The NIST SP 800-63B-4 technical standard requires at least 15 characters for single-factor passwords, at least 8 for passwords as part of multi-factor authentication, and forbids forced character-type rules (as of 2026).
| Issuer | Recommendation |
|---|---|
| BSI | Short and complex: at least 8, ideally 12 characters with four character types, or very long with at least 25 characters and two character types. For Wi-Fi at least 20 characters. |
| Verbraucherzentrale | At least 8, ideally 12 characters with four character types, from 25 characters two suffice. A separate password for every service, 2FA where possible. |
| NIST SP 800-63B-4 | Single-factor passwords at least 15 characters, at least 8 with multi-factor use, no additional character-class rules, blocklist of compromised passwords. |
| BSI on password changes | No routine, unreasoned password changes. Change if compromise is suspected. |
A surprising result of these guidelines: the special-character shuffle is out. Forced mixes of upper and lower case, numbers and symbols often lead to predictable variants like "Password1!". Instead, services rely on length and block common or already leaked passwords. For you that means choosing a long, random, unique password instead of forcing a short one with many special characters.
Still, no password value guarantees protection against phishing, malware or a database theft. That is why an important account always gets a second factor on top.
Passphrases: long, memorable, unique
A passphrase is a password made of several words. It is often easier to remember and type than a random string of the same length, and it is precisely strong when the words are chosen randomly and independently, not as a known saying or personal sentence. Four or more randomly chosen words are a sensible starting point.
Our Passphrase Generator combines several random words from a large list into a memorable unit. A passphrase is ideal for secrets you have to type yourself, such as the master password of your password manager. For ordinary accounts, a cryptographically random password in a manager is usually the better choice. The Password Mnemonic helps you reliably remember a single password you chose yourself.

Password managers: the easy way to unique passwords
A password manager collects all credentials in an encrypted vault. Depending on the product, the vault sits locally on one device or is synced encrypted with a cloud service. You unlock it with a master password, biometrics or an additional factor. Managers create unique passwords, sort logins by service and fill credentials only on the matching domain, which also helps against phishing.
Five things matter when choosing: the platforms your whole household uses, the kind of sync (cloud with end-to-end encryption or a local file), independent audits and clear encryption, a workable recovery if you forget the master password or lose a device, and the cost after the trial period.
| Provider | Storage and open source | Approx. cost, private |
|---|---|---|
| Bitwarden | Cloud sync, end-to-end encryption, open source | Free base, Premium about 19.80 US dollars a year, Family about 47.88 dollars |
| 1Password | Cloud sync, proprietary | Individual regularly about 3.99 US dollars a month, Family about 5.99 dollars |
| Proton Pass | Cloud sync, end-to-end encryption, open source | Free tier available, Pass Plus price depends |
| KeePass 2 | Local encrypted database file, open source | 0 euros |
Prices change with country, currency, taxes and billing interval, and the figures are rough magnitudes from official provider information. What matters for the master password: long, unique and used nowhere else. With a cloud manager, also turn on two-factor authentication for the manager account. If you forget your master password, you can lose access permanently depending on the product, so understand the recovery route beforehand.
A manager does not replace device updates or two-factor authentication. But it makes unique passwords practical instead of impossible. That lets you stop memorizing passwords: the Password Generator creates a fresh value for each account, and the Password Strengthener shows how to improve a weak choice until you have strengthened the password and kept it unique everywhere.
Two-factor authentication: the second lock
Even a strong password becomes useless if it is stolen. Two-factor authentication (2FA) requires a factor alongside knowledge (password), usually something you have (device, security key) or are (biometrics). MFA is the umbrella term for two or more factors. Two codes or two passwords are not automatically two different factors, what matters is that the categories differ.
| Method | Security profile | Convenience | Cost |
|---|---|---|---|
| TOTP in authenticator app | Good against password theft and SIM swapping, codes can be intercepted through real-time phishing | Medium, read and enter a code | Usually free |
| SMS code | Weakest common option because of SIM swapping and telecom risks | High, code arrives automatically | Usually no separate cost |
| Push confirmation | Good, prone to careless confirmation, phishing depending on implementation | High, accept or decline | Usually free |
| Hardware security key | Very high and phishing-resistant with correct FIDO2/WebAuthn | Medium, have the key ready | One-time purchase |
| Backup/recovery codes | One-time emergency codes, good for recovery | Low in daily use, high in emergencies | Free |
| Passkey | Very high against phishing and password reuse | Very high, device PIN or biometrics | Usually no extra cost |
No method is absolutely secure independent of device, implementation and recovery. CISA ranks FIDO and WebAuthn as phishing-resistant MFA and explicitly names SMS risks such as SIM swapping (as of 2023-01). For the main email account, banking, the password manager and accounts with recovery functions, choose the strongest practical option, usually TOTP or a passkey.
TOTP in practice: at setup, the service and the app share a secret seed, from which both calculate a time-based one-time code in sync, by default every 30 seconds (as of 2011-05). The QR code at setup contains this secret seed and must not end up in screenshots, chats or unencrypted notes. To set up, scan the code only in the installed authenticator app, confirm a one-time code and immediately save the offered recovery or backup codes. Established apps are Google Authenticator, Aegis (Android, open source), Ente Auth or Bitwarden Authenticator.
Passkeys: the passwordless login
A passkey replaces the password with public-key cryptography. At setup, your device creates a key pair: the private key stays with you, the service stores only the public key. At login, the service presents a challenge that your device signs with the private key, released locally via PIN or biometrics. Your biometric data never leaves the device. Because the login is bound to the registered website, a passkey reliably protects against classic phishing (as of 2026).
| Feature | Password | Passkey |
|---|---|---|
| Secret | User and service check a password | Private key stays on the device, service has only the public key |
| Phishing | Password can be entered on a fake page | Login is bound to the registered website |
| Reuse | A common risk | One key per website |
| Operation | Remember, type or fill via manager | Unlock device and confirm locally |
| Recovery | Account reset at the service | Sync provider, device access and recovery procedure |
Adoption is growing quickly. FIDO Alliance reports from a consumer survey of 11,000 adults in ten countries, including Germany: 90 percent know passkeys, 75 percent have activated at least one, 49 percent use them regularly when available, and FIDO estimates about five billion active passkeys worldwide (as of 2026). These values are global, not a specific German share. The BSI published TR-03188 in 2026 as a standard for operators of passkey servers (as of 2026).
Whether the passkey stays on the device or syncs to a cloud decides comfort and recovery. Synchronised passkeys (via iOS Keychain, Google or Windows Hello) are more convenient but depend on the provider's account recovery. Device-bound passkeys never leave the device but can lock you out if lost, unless a second key or another recovery path is registered. If a service handles passkeys well, activate them, but keep a second path and recovery codes ready for critical accounts.

Backup and recovery: the underestimated part
Most lockouts do not come from an attack but from a lost phone or a forgotten master password. That is why recovery codes and backups belong to security. Recovery codes are one-time replacement keys that you should save immediately after creation, ideally offline and separate from the phone, not in unencrypted screenshots, emails or cloud notes. If a code is used, mark it as spent, and revoke it if exposure is suspected.
The same applies to the authenticator app: TOTP seeds must be transferable to a new device before loss or reset, via encrypted export, app sync or a fresh setup in every service. Reinstalling the app alone does not restore the seeds. An encrypted backup without a rememberable password does not help in an emergency.
If you lose a device: first secure access to your email account and password manager, then restore authenticator and passkey backups, and finally remove old devices and sessions at the services. Set up at least two independent routes for your most important accounts in advance, such as a passkey plus recovery codes, or a primary plus a spare security key. Support staff never ask for your master password, complete seeds or recovery codes, and you never give them out.
About the device PIN: four to six digits are a common length but not a guarantee. A PIN that only unlocks a local device is not the same as a password for an online account sent to a server, which is exposed to rate-based attacks there (as of 2025-07). A random, non-reused PIN instead of a birthday helps, and our PIN Generator provides a suggestion.
Securing your Wi-Fi: protecting the home network
The router is the central door to your home. A compromised router or a weak Wi-Fi password can endanger many devices at once. The BSI recommends at least WPA2 for Wi-Fi, ideally WPA3 (as of 2026). WPA3 makes offline dictionary attacks much harder but needs devices that support it. A transition mode brings in older devices but does not offer the full protection throughout.
| Feature | WPA2-Personal | WPA3-Personal |
|---|---|---|
| Authentication | Shared network key (PSK) | Modern handshake (SAE) |
| Weak Wi-Fi password | Offline attacks on recorded handshakes possible | Offline dictionary attacks harder |
| Older devices | Very widely supported | Older devices may be incompatible |
| Minimum level | WPA2 with AES (CCMP) | WPA3 |
The important point: WPA3 does not protect against weak passwords either. The Wi-Fi key should be long, random and valid for only this one network. The BSI recommends at least 20 unrelated characters for a guest network, WPA2 minimum or WPA3 if available.
Seven steps to a secure setup:
- Log into the router admin interface and replace the factory admin password with a long, one-time password that is not the Wi-Fi password. The Password Generator helps create it.
- Set Wi-Fi security to WPA3 if all devices are compatible, otherwise WPA2-AES. Do not use outdated WEP or TKIP/WPA.
- Set a separate, random Wi-Fi password, different from the router admin.
- Enable a guest network with its own password and isolation from the home network. Put smart TVs, cameras, speakers and other connected devices there if possible.
- Disable WPS, especially the PIN method, if it is not needed.
- Switch off remote admin of the router unless you deliberately need it.
- Enable automatic firmware updates or check regularly.
Friends and guests get only the guest access. If you share it as a QR code, generate the code for the guest network and do not display it publicly or post it online, because a QR code hands the access data to anyone who scans or photographs it. The Wi-Fi QR Generator creates suitable codes, for the main network it is off limits.
Recognising phishing, smishing and vishing
Phishing is the most common way to obtain credentials. Fake emails, texts and calls pose as your bank, a parcel service, an authority or support. Good language, a correct logo and a professional layout are not proof of authenticity. According to the 2026 Cybersicherheitsmonitor by BSI and Polizeiliche Kriminalprävention, 11 percent of internet users became victims of a crime online in the previous year, most often online shopping fraud (22 percent of those affected), followed by unauthorised access to online accounts (14 percent), online banking fraud (13 percent) and phishing (12 percent). 88 percent of those affected reported some harm, a third financial losses (as of 2026-05-11).
| Signal | Why it is suspicious | Safe next step |
|---|---|---|
| Time pressure, freezing or threats | Meant to stop careful checking | Do not reply, contact the sender via a known channel |
| Link to login, payment or data check | Can lead to a lookalike website | Type in the website yourself or use a bookmark |
| Parcel fee, customs or missing address | A common smishing pretext | Check the shipment in the official app with the real tracking number |
| Unexpected invoice or demand | Sender name and logo are easy to imitate | Check order and account independently |
| Call asks for TAN, password or remote access | Legitimate parties never ask for secrets | Hang up, look up the number yourself |
| QR code on an invoice or letter | The target is hard to see before scanning | Check the URL, in doubt open the website manually |
| Sender address differs slightly | Similar letters and subdomains deceive | Read the full domain, not just the logo |
Smishing (by text) most often uses parcel fees and delivery problems, vishing (by call) a supposed bank, police or support with a spoofed caller ID. The Verbraucherzentrale documents current patterns in its phishing radar. Never give out TANs, one-time codes, passwords or remote access on the phone.
If you clicked, what to do? A mere click without entering data does not automatically make your device sick, close the tab and enter nothing. If you entered a password, change it immediately via the genuine website or app and replace it everywhere you reused it, starting with the email account and payment services. If you gave out bank or card data or approved a payment, contact your bank immediately on its official number and have the account, card or access blocked, if needed via the emergency number 116 116. If you shared a one-time code or approval, contact the service at once and revoke sessions. Save evidence, screenshots and timestamps and file a report with the police.
Checking whether your password is in a breach
To find out whether an email address or password appears in known data breaches, the best check is Have I Been Pwned (haveibeenpwned.com). A hit shows the address appeared in a known incident, not that the account was just taken over. No hit does not prove nothing was ever exposed, the database covers only known and recorded breaches. HIBP's password check, Pwned Passwords, builds a hash locally and sends only its start to the API, the password never leaves your computer (as of 2026).
Scale makes the extent clear: the June 2026 Stealer Logs dataset at HIBP records 56.3 million affected email accounts and 124 million unique passwords, merged stealer logs from various sources rather than a single hacked service (as of 2026-06-15). The roughly 24 billion credential records reported in 2026 are not a count of unique people, and source and deduplication remain unclear. The share of reused passwords in leaked corpora is sometimes given as over 90 percent, referring to the investigated dataset, not to all people. That is why a unique password per service is so valuable.
After a reported data breach:
- Check which data was exposed at the affected service, only via the official announcement, not via links from alarming emails.
- Change the password through the genuine website or app.
- Replace every reused password on all other accounts too, starting with email, banking, payment services and the mobile account.
- Turn on two-factor authentication or a passkey.
- Log out old sessions, remove unknown devices and forwarding rules, check the recovery address and phone number.
- Watch for fraudulent messages in the coming weeks that use your real data from the breach as bait.
- Contact the bank and the police if there is financial harm.
The Password Checker tells you whether a password pattern is too weak. Important: never copy a current valid password into unknown pages, and replace a password that was in a breach everywhere instead of changing only one character.
Keeping browsers and devices clean
Security updates are the foundation under every other measure. Enable automatic updates for the operating system, browser, extensions and apps, and do not postpone a restart forever. Outdated software carries known vulnerabilities.
| Area | Recommendation | Trade-off |
|---|---|---|
| Security updates | Enable automatic updates, do not postpone restart | Outdated software keeps known vulnerabilities |
| Browser password storage | Better than reuse, but secure device and browser account | Malware can read credentials from browsers |
| Standalone password manager | Strong master password and 2FA, secure recovery | A compromised vault can affect many accounts |
| Cookies | Delete history and site data regularly, limit third-party cookies | Logout and loss of saved baskets possible |
The BSI password manager guide makes it clear: a well-secured browser vault is generally better than identical or weak passwords. A standalone password manager offers a central encrypted vault with a strong master password. Either way: lock the device, keep the browser current and use unique passwords. Allow autofill only on the correct domain, especially after clicks on links from messages.
Cookie hygiene is primarily data protection, not phishing defence. Private windows delete session data on closing but do not prevent malware or the capture of data you actively enter. Incognito mode therefore does not protect against phishing.
Connected homes also have open standard access points: routers, smart TVs, cameras, NAS and other devices often carry a factory admin password that you should change if the device allows it. Use a strong, individual password for every device, keep firmware and apps current, and switch off unneeded remote access and services. Devices with low trust belong in the separate guest or IoT network. If you pass on or dispose of an old device, reset it to factory settings and remove linked cloud accounts.
The household checklist
- The email account has its own strong password and 2FA or a passkey.
- No password is reused across multiple services.
- A password manager is set up, the master password is unique and recovery is clear.
- The router admin password is changed and not identical to the Wi-Fi password.
- Wi-Fi runs on WPA2-AES, preferably WPA3, and the key is long and unique.
- A guest network is enabled, guests and, where possible, connected devices are separated from the home network.
- The WPS PIN method and unneeded remote admin are disabled.
- Devices, browsers and the password manager receive security updates.
- Smart TVs and connected devices have no unchanged standard access points.
- Recovery codes and authenticator backups are kept safely separate from the phone.
- Everyone in the household never gives TANs, passwords or one-time codes over the phone.
If you want to work through every point, the best way is Security Setup, the step-by-step playbook for this handbook. It brings accounts, Wi-Fi, devices and recovery together in a sensible order.
Frequently asked questions
How long should a password be at least in 2026?
Are special characters still necessary in a password?
Is a four-word passphrase secure?
Can a password manager itself be hacked?
Which 2FA method is most secure: SMS, app or security key?
What is a passkey and how does it replace a password?
What do I do if my password appears in a data breach?
Is WPA2 still secure or do I need WPA3 in 2026?
Is it safe to share my Wi-Fi password as a QR code?
How long should my home Wi-Fi password be?
How do I spot phishing and what do I do if I clicked?
Are passwords saved in the browser secure?
This handbook is a general orientation guide and does not replace individual security or legal advice. Recommendations from the BSI, Verbraucherzentrale, NIST and the FIDO Alliance, as well as prices and features of products, can change, and many details depend on device, service and provider. Figures and values were checked on 7 October 2026 unless stated otherwise.
Sources & status of these figures
The statements in this handbook come from the sources named (BSI, Germany's Federal Office for Information Security, Verbraucherzentrale, NIST, FIDO Alliance, CISA, FTC, Have I Been Pwned, Polizeiliche Kriminalprävention) and were last checked on 7 October 2026. Each current figure carries a status date. The tools on this site process inputs locally in the browser.
- BSI: Creating secure passwords, minimum lengths and recommendations. bsi.bund.de
- BSI: Press release of 31.01.2025, no routine password changes. bsi.bund.de
- Verbraucherzentrale: Creating strong passwords and password managers. verbraucherzentrale.de
- NIST SP 800-63B-4: Requirements for passwords and authenticators, published 31.07.2025. pages.nist.gov
- OWASP: Password Storage Cheat Sheet, Argon2id and bcrypt. cheatsheetseries.owasp.org
- Have I Been Pwned: June 2026 Stealer Logs, 56.3 million affected email accounts, dataset added 15.06.2026. haveibeenpwned.com
- Have I Been Pwned: Pwned Passwords, k-anonymity, check service for compromised passwords. haveibeenpwned.com
- BSI: Two-factor authentication and passkeys. bsi.bund.de
- BSI: TR-03188 for passkey servers, published 30.06.2026. bsi.bund.de
- FIDO Alliance: State of Passkeys 2026, global consumer survey, April 2026. fidoalliance.org
- CISA: Fact sheet, phishing-resistant MFA and SMS risks. cisa.gov
- FTC: SIM Swap Scams, Consumer Alert. consumer.ftc.gov
- IETF: RFC 6238, TOTP algorithm and 30-second step. rfc-editor.org
- BSI: Step by step to a guest Wi-Fi, WPA2/WPA3, 20 characters for the guest network. bsi.bund.de
- BSI and Polizeiliche Kriminalprävention: Cybersicherheitsmonitor 2026, survey of 3,060 people, January 2026. bsi.bund.de
- Polizeiliche Kriminalprävention: Recognising phishing and fake shops. polizei-beratung.de
- Verbraucherzentrale: Phishing radar and parcel service SMS. verbraucherzentrale.de
- rbb: GMX and WEB.DE, spam volume in the first half of 2026, September 2026. rbb-online.de
- Have I Been Pwned: Email breach search and notifications. haveibeenpwned.com
- AVM: Sharing Wi-Fi access via QR code and guest access. avm.de