Title graphic: Passwords & Home Online Security, the 2026 guide

Security

Passwords & Home Online Security: The 2026 Guide

By Daniel Ohiggins · Published: October 7, 2026 · 18 min read

Passwords and home online security: the short answer

No password is a guarantee on its own. But the order of protection is clear: a long, unique password for every service, ideally from a password manager, plus two-factor authentication or a passkey for all important accounts. For the home network you add a strong, unique Wi-Fi password, WPA2 or WPA3 and a separate guest network. Doing these basics covers the most common attack paths: guessed or reused passwords, data breaches, phishing and insecure Wi-Fi.

The Password Generator creates a random, unique password for each account, and the Password Checker tells you whether a password pattern is already known and too weak. Our Security Setup playbook walks you through setting up your most important accounts and devices step by step.

A metal padlock with key, a symbol for encryption and access protection

Why a password alone is not enough

A password is only a single knowledge factor. If it is guessed, reused, captured through phishing or taken from a data breach, it opens access immediately. Attackers use very different techniques, and the right defence depends on the type of attack.

TechniqueWhat happensWhat helps
Brute forceA program systematically tries combinations of characters.Length, rate limits, two-factor authentication, passkeys
Dictionary attackCommon words, names and keyboard patterns are guessed.Do not use dictionary words or personal details on their own
Rule-based attackKnown words are varied by patterns, such as a capital first letter, a digit at the end.No predictable replacements, better random passwords or passphrases
Credential stuffingStolen email and password combinations are tried automatically on other services.A unique password per service, 2FA or passkey
Phishing and infostealersCredentials are captured on fake pages or stolen directly from a device.Check the URL, use a passkey, protect the device, revoke sessions

With an online login, the service can limit or delay login attempts. With an offline attack, the attacker instead holds a stolen password database and can attack the hashes at leisure. How well you are protected then depends on how the service stored the password. A service should never keep passwords in plain text, but should derive a hash with an adaptive method. MD5 and SHA-1 are unsuitable because they compute too fast. bcrypt is still common, and Argon2id is the recommended modern choice, both deliberately slow and memory-intensive (as of 2026).

A salt is a random per-password value mixed in during hashing. It ensures that the same password produces different hash values for two accounts and makes precomputed rainbow tables useless. It does not, however, make a weak password strong.

The most important lesson for everyday life: length beats a predictable complexity pattern. More independent random characters enlarge the search space more than forced special characters that many people place in the same way. What counts is unique, random passwords that are new for every service.

What really makes a strong password in 2026

The recommendations of the authorities are now surprisingly aligned, even if they are worded differently. The BSI and the Verbraucherzentrale give two paths: a shorter, complex password with at least 8, ideally 12 characters and four character types, or a longer one with at least 25 characters and at least two character types. The NIST SP 800-63B-4 technical standard requires at least 15 characters for single-factor passwords, at least 8 for passwords as part of multi-factor authentication, and forbids forced character-type rules (as of 2026).

IssuerRecommendation
BSIShort and complex: at least 8, ideally 12 characters with four character types, or very long with at least 25 characters and two character types. For Wi-Fi at least 20 characters.
VerbraucherzentraleAt least 8, ideally 12 characters with four character types, from 25 characters two suffice. A separate password for every service, 2FA where possible.
NIST SP 800-63B-4Single-factor passwords at least 15 characters, at least 8 with multi-factor use, no additional character-class rules, blocklist of compromised passwords.
BSI on password changesNo routine, unreasoned password changes. Change if compromise is suspected.

A surprising result of these guidelines: the special-character shuffle is out. Forced mixes of upper and lower case, numbers and symbols often lead to predictable variants like "Password1!". Instead, services rely on length and block common or already leaked passwords. For you that means choosing a long, random, unique password instead of forcing a short one with many special characters.

Still, no password value guarantees protection against phishing, malware or a database theft. That is why an important account always gets a second factor on top.

Passphrases: long, memorable, unique

A passphrase is a password made of several words. It is often easier to remember and type than a random string of the same length, and it is precisely strong when the words are chosen randomly and independently, not as a known saying or personal sentence. Four or more randomly chosen words are a sensible starting point.

Our Passphrase Generator combines several random words from a large list into a memorable unit. A passphrase is ideal for secrets you have to type yourself, such as the master password of your password manager. For ordinary accounts, a cryptographically random password in a manager is usually the better choice. The Password Mnemonic helps you reliably remember a single password you chose yourself.

A padlock with its interior open, a symbol for how the mechanism works

Password managers: the easy way to unique passwords

A password manager collects all credentials in an encrypted vault. Depending on the product, the vault sits locally on one device or is synced encrypted with a cloud service. You unlock it with a master password, biometrics or an additional factor. Managers create unique passwords, sort logins by service and fill credentials only on the matching domain, which also helps against phishing.

Five things matter when choosing: the platforms your whole household uses, the kind of sync (cloud with end-to-end encryption or a local file), independent audits and clear encryption, a workable recovery if you forget the master password or lose a device, and the cost after the trial period.

ProviderStorage and open sourceApprox. cost, private
BitwardenCloud sync, end-to-end encryption, open sourceFree base, Premium about 19.80 US dollars a year, Family about 47.88 dollars
1PasswordCloud sync, proprietaryIndividual regularly about 3.99 US dollars a month, Family about 5.99 dollars
Proton PassCloud sync, end-to-end encryption, open sourceFree tier available, Pass Plus price depends
KeePass 2Local encrypted database file, open source0 euros

Prices change with country, currency, taxes and billing interval, and the figures are rough magnitudes from official provider information. What matters for the master password: long, unique and used nowhere else. With a cloud manager, also turn on two-factor authentication for the manager account. If you forget your master password, you can lose access permanently depending on the product, so understand the recovery route beforehand.

A manager does not replace device updates or two-factor authentication. But it makes unique passwords practical instead of impossible. That lets you stop memorizing passwords: the Password Generator creates a fresh value for each account, and the Password Strengthener shows how to improve a weak choice until you have strengthened the password and kept it unique everywhere.

Two-factor authentication: the second lock

Even a strong password becomes useless if it is stolen. Two-factor authentication (2FA) requires a factor alongside knowledge (password), usually something you have (device, security key) or are (biometrics). MFA is the umbrella term for two or more factors. Two codes or two passwords are not automatically two different factors, what matters is that the categories differ.

MethodSecurity profileConvenienceCost
TOTP in authenticator appGood against password theft and SIM swapping, codes can be intercepted through real-time phishingMedium, read and enter a codeUsually free
SMS codeWeakest common option because of SIM swapping and telecom risksHigh, code arrives automaticallyUsually no separate cost
Push confirmationGood, prone to careless confirmation, phishing depending on implementationHigh, accept or declineUsually free
Hardware security keyVery high and phishing-resistant with correct FIDO2/WebAuthnMedium, have the key readyOne-time purchase
Backup/recovery codesOne-time emergency codes, good for recoveryLow in daily use, high in emergenciesFree
PasskeyVery high against phishing and password reuseVery high, device PIN or biometricsUsually no extra cost

No method is absolutely secure independent of device, implementation and recovery. CISA ranks FIDO and WebAuthn as phishing-resistant MFA and explicitly names SMS risks such as SIM swapping (as of 2023-01). For the main email account, banking, the password manager and accounts with recovery functions, choose the strongest practical option, usually TOTP or a passkey.

TOTP in practice: at setup, the service and the app share a secret seed, from which both calculate a time-based one-time code in sync, by default every 30 seconds (as of 2011-05). The QR code at setup contains this secret seed and must not end up in screenshots, chats or unencrypted notes. To set up, scan the code only in the installed authenticator app, confirm a one-time code and immediately save the offered recovery or backup codes. Established apps are Google Authenticator, Aegis (Android, open source), Ente Auth or Bitwarden Authenticator.

Passkeys: the passwordless login

A passkey replaces the password with public-key cryptography. At setup, your device creates a key pair: the private key stays with you, the service stores only the public key. At login, the service presents a challenge that your device signs with the private key, released locally via PIN or biometrics. Your biometric data never leaves the device. Because the login is bound to the registered website, a passkey reliably protects against classic phishing (as of 2026).

FeaturePasswordPasskey
SecretUser and service check a passwordPrivate key stays on the device, service has only the public key
PhishingPassword can be entered on a fake pageLogin is bound to the registered website
ReuseA common riskOne key per website
OperationRemember, type or fill via managerUnlock device and confirm locally
RecoveryAccount reset at the serviceSync provider, device access and recovery procedure

Adoption is growing quickly. FIDO Alliance reports from a consumer survey of 11,000 adults in ten countries, including Germany: 90 percent know passkeys, 75 percent have activated at least one, 49 percent use them regularly when available, and FIDO estimates about five billion active passkeys worldwide (as of 2026). These values are global, not a specific German share. The BSI published TR-03188 in 2026 as a standard for operators of passkey servers (as of 2026).

Whether the passkey stays on the device or syncs to a cloud decides comfort and recovery. Synchronised passkeys (via iOS Keychain, Google or Windows Hello) are more convenient but depend on the provider's account recovery. Device-bound passkeys never leave the device but can lock you out if lost, unless a second key or another recovery path is registered. If a service handles passkeys well, activate them, but keep a second path and recovery codes ready for critical accounts.

Keys and a light bulb on a wooden table, a symbol for access and solutions

Backup and recovery: the underestimated part

Most lockouts do not come from an attack but from a lost phone or a forgotten master password. That is why recovery codes and backups belong to security. Recovery codes are one-time replacement keys that you should save immediately after creation, ideally offline and separate from the phone, not in unencrypted screenshots, emails or cloud notes. If a code is used, mark it as spent, and revoke it if exposure is suspected.

The same applies to the authenticator app: TOTP seeds must be transferable to a new device before loss or reset, via encrypted export, app sync or a fresh setup in every service. Reinstalling the app alone does not restore the seeds. An encrypted backup without a rememberable password does not help in an emergency.

If you lose a device: first secure access to your email account and password manager, then restore authenticator and passkey backups, and finally remove old devices and sessions at the services. Set up at least two independent routes for your most important accounts in advance, such as a passkey plus recovery codes, or a primary plus a spare security key. Support staff never ask for your master password, complete seeds or recovery codes, and you never give them out.

About the device PIN: four to six digits are a common length but not a guarantee. A PIN that only unlocks a local device is not the same as a password for an online account sent to a server, which is exposed to rate-based attacks there (as of 2025-07). A random, non-reused PIN instead of a birthday helps, and our PIN Generator provides a suggestion.

Securing your Wi-Fi: protecting the home network

The router is the central door to your home. A compromised router or a weak Wi-Fi password can endanger many devices at once. The BSI recommends at least WPA2 for Wi-Fi, ideally WPA3 (as of 2026). WPA3 makes offline dictionary attacks much harder but needs devices that support it. A transition mode brings in older devices but does not offer the full protection throughout.

FeatureWPA2-PersonalWPA3-Personal
AuthenticationShared network key (PSK)Modern handshake (SAE)
Weak Wi-Fi passwordOffline attacks on recorded handshakes possibleOffline dictionary attacks harder
Older devicesVery widely supportedOlder devices may be incompatible
Minimum levelWPA2 with AES (CCMP)WPA3

The important point: WPA3 does not protect against weak passwords either. The Wi-Fi key should be long, random and valid for only this one network. The BSI recommends at least 20 unrelated characters for a guest network, WPA2 minimum or WPA3 if available.

Seven steps to a secure setup:

  1. Log into the router admin interface and replace the factory admin password with a long, one-time password that is not the Wi-Fi password. The Password Generator helps create it.
  2. Set Wi-Fi security to WPA3 if all devices are compatible, otherwise WPA2-AES. Do not use outdated WEP or TKIP/WPA.
  3. Set a separate, random Wi-Fi password, different from the router admin.
  4. Enable a guest network with its own password and isolation from the home network. Put smart TVs, cameras, speakers and other connected devices there if possible.
  5. Disable WPS, especially the PIN method, if it is not needed.
  6. Switch off remote admin of the router unless you deliberately need it.
  7. Enable automatic firmware updates or check regularly.

Friends and guests get only the guest access. If you share it as a QR code, generate the code for the guest network and do not display it publicly or post it online, because a QR code hands the access data to anyone who scans or photographs it. The Wi-Fi QR Generator creates suitable codes, for the main network it is off limits.

Recognising phishing, smishing and vishing

Phishing is the most common way to obtain credentials. Fake emails, texts and calls pose as your bank, a parcel service, an authority or support. Good language, a correct logo and a professional layout are not proof of authenticity. According to the 2026 Cybersicherheitsmonitor by BSI and Polizeiliche Kriminalprävention, 11 percent of internet users became victims of a crime online in the previous year, most often online shopping fraud (22 percent of those affected), followed by unauthorised access to online accounts (14 percent), online banking fraud (13 percent) and phishing (12 percent). 88 percent of those affected reported some harm, a third financial losses (as of 2026-05-11).

SignalWhy it is suspiciousSafe next step
Time pressure, freezing or threatsMeant to stop careful checkingDo not reply, contact the sender via a known channel
Link to login, payment or data checkCan lead to a lookalike websiteType in the website yourself or use a bookmark
Parcel fee, customs or missing addressA common smishing pretextCheck the shipment in the official app with the real tracking number
Unexpected invoice or demandSender name and logo are easy to imitateCheck order and account independently
Call asks for TAN, password or remote accessLegitimate parties never ask for secretsHang up, look up the number yourself
QR code on an invoice or letterThe target is hard to see before scanningCheck the URL, in doubt open the website manually
Sender address differs slightlySimilar letters and subdomains deceiveRead the full domain, not just the logo

Smishing (by text) most often uses parcel fees and delivery problems, vishing (by call) a supposed bank, police or support with a spoofed caller ID. The Verbraucherzentrale documents current patterns in its phishing radar. Never give out TANs, one-time codes, passwords or remote access on the phone.

If you clicked, what to do? A mere click without entering data does not automatically make your device sick, close the tab and enter nothing. If you entered a password, change it immediately via the genuine website or app and replace it everywhere you reused it, starting with the email account and payment services. If you gave out bank or card data or approved a payment, contact your bank immediately on its official number and have the account, card or access blocked, if needed via the emergency number 116 116. If you shared a one-time code or approval, contact the service at once and revoke sessions. Save evidence, screenshots and timestamps and file a report with the police.

Checking whether your password is in a breach

To find out whether an email address or password appears in known data breaches, the best check is Have I Been Pwned (haveibeenpwned.com). A hit shows the address appeared in a known incident, not that the account was just taken over. No hit does not prove nothing was ever exposed, the database covers only known and recorded breaches. HIBP's password check, Pwned Passwords, builds a hash locally and sends only its start to the API, the password never leaves your computer (as of 2026).

Scale makes the extent clear: the June 2026 Stealer Logs dataset at HIBP records 56.3 million affected email accounts and 124 million unique passwords, merged stealer logs from various sources rather than a single hacked service (as of 2026-06-15). The roughly 24 billion credential records reported in 2026 are not a count of unique people, and source and deduplication remain unclear. The share of reused passwords in leaked corpora is sometimes given as over 90 percent, referring to the investigated dataset, not to all people. That is why a unique password per service is so valuable.

After a reported data breach:

  1. Check which data was exposed at the affected service, only via the official announcement, not via links from alarming emails.
  2. Change the password through the genuine website or app.
  3. Replace every reused password on all other accounts too, starting with email, banking, payment services and the mobile account.
  4. Turn on two-factor authentication or a passkey.
  5. Log out old sessions, remove unknown devices and forwarding rules, check the recovery address and phone number.
  6. Watch for fraudulent messages in the coming weeks that use your real data from the breach as bait.
  7. Contact the bank and the police if there is financial harm.

The Password Checker tells you whether a password pattern is too weak. Important: never copy a current valid password into unknown pages, and replace a password that was in a breach everywhere instead of changing only one character.

Keeping browsers and devices clean

Security updates are the foundation under every other measure. Enable automatic updates for the operating system, browser, extensions and apps, and do not postpone a restart forever. Outdated software carries known vulnerabilities.

AreaRecommendationTrade-off
Security updatesEnable automatic updates, do not postpone restartOutdated software keeps known vulnerabilities
Browser password storageBetter than reuse, but secure device and browser accountMalware can read credentials from browsers
Standalone password managerStrong master password and 2FA, secure recoveryA compromised vault can affect many accounts
CookiesDelete history and site data regularly, limit third-party cookiesLogout and loss of saved baskets possible

The BSI password manager guide makes it clear: a well-secured browser vault is generally better than identical or weak passwords. A standalone password manager offers a central encrypted vault with a strong master password. Either way: lock the device, keep the browser current and use unique passwords. Allow autofill only on the correct domain, especially after clicks on links from messages.

Cookie hygiene is primarily data protection, not phishing defence. Private windows delete session data on closing but do not prevent malware or the capture of data you actively enter. Incognito mode therefore does not protect against phishing.

Connected homes also have open standard access points: routers, smart TVs, cameras, NAS and other devices often carry a factory admin password that you should change if the device allows it. Use a strong, individual password for every device, keep firmware and apps current, and switch off unneeded remote access and services. Devices with low trust belong in the separate guest or IoT network. If you pass on or dispose of an old device, reset it to factory settings and remove linked cloud accounts.

The household checklist

  • The email account has its own strong password and 2FA or a passkey.
  • No password is reused across multiple services.
  • A password manager is set up, the master password is unique and recovery is clear.
  • The router admin password is changed and not identical to the Wi-Fi password.
  • Wi-Fi runs on WPA2-AES, preferably WPA3, and the key is long and unique.
  • A guest network is enabled, guests and, where possible, connected devices are separated from the home network.
  • The WPS PIN method and unneeded remote admin are disabled.
  • Devices, browsers and the password manager receive security updates.
  • Smart TVs and connected devices have no unchanged standard access points.
  • Recovery codes and authenticator backups are kept safely separate from the phone.
  • Everyone in the household never gives TANs, passwords or one-time codes over the phone.

If you want to work through every point, the best way is Security Setup, the step-by-step playbook for this handbook. It brings accounts, Wi-Fi, devices and recovery together in a sensible order.

Frequently asked questions

How long should a password be at least in 2026?
Germany's BSI and the consumer advice centre Verbraucherzentrale give two options: a shorter, complex password with at least 8, ideally 12 characters and four character types, or a longer one with at least 25 characters and at least two character types. The NIST SP 800-63B-4 standard requires at least 15 characters for single-factor passwords. For important accounts, use a long, random, unique password from a password manager, different for every service.
Are special characters still necessary in a password?
Not as a requirement. Current guidance puts length before forced character types, because people often respond to forced rules with predictable variants and maximum length limits can shorten the real password. What matters is that the password is long, unique and not known from a data breach. Whether complexity is mandatory is set by each service.
Is a four-word passphrase secure?
A passphrase of four or more randomly and independently chosen words is a good basis for a memorable long secret, such as your password manager's master password. It is only strong if the words are truly random and not a known saying or personal sentence. For ordinary accounts, a randomly generated password in a manager is usually the better choice.
Can a password manager itself be hacked?
A password manager is an attractive target, which is why its encryption matters. Trustworthy providers encrypt the vault with a strong, long master password that never leaves the server. A limited residual risk remains, so also secure the manager account with two-factor authentication or a passkey and keep your devices up to date.
Which 2FA method is most secure: SMS, app or security key?
Hardware security keys and passkeys are the strongest, because they are phishing-resistant and bound to the genuine website. Authenticator apps (TOTP) are good and free but can be intercepted through real-time phishing under pressure. SMS is the weakest common option because of SIM swapping and should be replaced where possible. Even the best factor helps little if you do not secure your recovery codes.
What is a passkey and how does it replace a password?
A passkey is a passwordless login based on public-key cryptography. When you set it up, your device creates a key pair, the private key stays with you and the service gets only the public key. You confirm the login locally with a PIN or biometrics. Because the passkey is bound to the registered website, it reliably protects against classic phishing. Whether it replaces your password depends on the service.
What do I do if my password appears in a data breach?
First change the password only through the service's genuine website or app, then replace the same password everywhere you reused it. Start with the email account and financial and payment services. Turn on two-factor authentication or a passkey, log out old sessions and watch for fraudulent messages in the following weeks that use your real data as bait.
Is WPA2 still secure or do I need WPA3 in 2026?
WPA3 is the better choice as soon as your router and devices support it, because it makes offline dictionary attacks harder. WPA2 with AES (CCMP) is still an acceptable minimum. If your router offers neither but only WEP or old WPA, replace it. A long, unique Wi-Fi password is equally important.
Is it safe to share my Wi-Fi password as a QR code?
Yes, if you generate the QR code only for the separate guest network and do not display it publicly or post it online. A QR code hands the access data to anyone who scans or photographs it. A code for the main network in the window or on social media is not a good idea.
How long should my home Wi-Fi password be?
For your main Wi-Fi you should use a long, random, unique password that is not identical to other passwords. Germany's BSI recommends at least 20 unrelated characters for a guest network. Your router admin password is a separate matter and must not be the same as the Wi-Fi password.
How do I spot phishing and what do I do if I clicked?
Warning signs are time pressure, account freezing or threats, links to login or payment, unexpected parcel fees, invoices or calls that demand TANs and passwords. If you only clicked, close the page and enter nothing. If you entered a password, change it immediately on the genuine website and replace it everywhere you reused it. If you approved a payment or gave out card details, contact your bank right away on its official number.
Are passwords saved in the browser secure?
Better than weak or reused passwords, but not perfect, because malware can read credentials stored in browsers. A well-secured browser vault is acceptable for many accounts. A standalone password manager offers a central encrypted vault with a strong master password. Either way: lock your device, keep the browser updated and use unique passwords.

This handbook is a general orientation guide and does not replace individual security or legal advice. Recommendations from the BSI, Verbraucherzentrale, NIST and the FIDO Alliance, as well as prices and features of products, can change, and many details depend on device, service and provider. Figures and values were checked on 7 October 2026 unless stated otherwise.

Sources & status of these figures

The statements in this handbook come from the sources named (BSI, Germany's Federal Office for Information Security, Verbraucherzentrale, NIST, FIDO Alliance, CISA, FTC, Have I Been Pwned, Polizeiliche Kriminalprävention) and were last checked on 7 October 2026. Each current figure carries a status date. The tools on this site process inputs locally in the browser.

  • BSI: Creating secure passwords, minimum lengths and recommendations. bsi.bund.de
  • BSI: Press release of 31.01.2025, no routine password changes. bsi.bund.de
  • Verbraucherzentrale: Creating strong passwords and password managers. verbraucherzentrale.de
  • NIST SP 800-63B-4: Requirements for passwords and authenticators, published 31.07.2025. pages.nist.gov
  • OWASP: Password Storage Cheat Sheet, Argon2id and bcrypt. cheatsheetseries.owasp.org
  • Have I Been Pwned: June 2026 Stealer Logs, 56.3 million affected email accounts, dataset added 15.06.2026. haveibeenpwned.com
  • Have I Been Pwned: Pwned Passwords, k-anonymity, check service for compromised passwords. haveibeenpwned.com
  • BSI: Two-factor authentication and passkeys. bsi.bund.de
  • BSI: TR-03188 for passkey servers, published 30.06.2026. bsi.bund.de
  • FIDO Alliance: State of Passkeys 2026, global consumer survey, April 2026. fidoalliance.org
  • CISA: Fact sheet, phishing-resistant MFA and SMS risks. cisa.gov
  • FTC: SIM Swap Scams, Consumer Alert. consumer.ftc.gov
  • IETF: RFC 6238, TOTP algorithm and 30-second step. rfc-editor.org
  • BSI: Step by step to a guest Wi-Fi, WPA2/WPA3, 20 characters for the guest network. bsi.bund.de
  • BSI and Polizeiliche Kriminalprävention: Cybersicherheitsmonitor 2026, survey of 3,060 people, January 2026. bsi.bund.de
  • Polizeiliche Kriminalprävention: Recognising phishing and fake shops. polizei-beratung.de
  • Verbraucherzentrale: Phishing radar and parcel service SMS. verbraucherzentrale.de
  • rbb: GMX and WEB.DE, spam volume in the first half of 2026, September 2026. rbb-online.de
  • Have I Been Pwned: Email breach search and notifications. haveibeenpwned.com
  • AVM: Sharing Wi-Fi access via QR code and guest access. avm.de