It's Okay to Write Your Passwords Down. Just Turn On the Second Lock.

I spend my days helping businesses keep their computers safe. But the question I get most often comes from friends, parents, and folks at church: "Andy, how do I keep my accounts from getting hacked?"

Here's my honest answer, especially if you're retired: you don't need to memorize a hundred complicated passwords. You need a second lock on the door.

Yes, you can write your passwords in a book

A lot of security advice says never to write passwords down. I disagree, at least for most people at home. A thief in Russia can't reach the notebook in your desk drawer. What they can do is guess, steal, or trick you out of a password online.

So go ahead and keep a password book. Just follow a few rules:

  • Keep it at home in a drawer, not in your purse, wallet, or car.
  • Don't label it "Passwords" on the cover.
  • Use a different password for every account. Reusing one password is the biggest mistake I see. When one website gets breached, crooks try that same password on your bank, your email, and your Amazon.
  • Tell one trusted family member where the book is.

A long password alone won't save you

People think a long, clever password keeps them safe. Length helps a little, but it doesn't stop the ways most accounts actually get stolen today:

  • A website you use gets breached and your password leaks.
  • You get a convincing email or text ("Your account is locked, click here") and type your password into a fake page.
  • Someone calls pretending to be your bank or Microsoft.

In every one of those cases, the crook has your password, however long it is. That's why you need the second lock.

The second lock: multi-factor authentication

Multi-factor authentication (MFA, sometimes called two-step verification) means that after you type your password, the website also asks for a short code that only you have. Usually that's a six-digit number from an app on your phone that changes every 30 seconds.

Even if a crook has your password, they don't have your phone. They're stuck at the door.

Turn it on for these first:

  1. Your email (Gmail, Yahoo, Outlook, AOL). Whoever controls your email can reset everything else.
  2. Your bank and credit card accounts.
  3. Amazon and any shopping site with your card saved.
  4. Facebook and any social media.
  5. Your Apple ID or Google account.

Look in each account's settings for "Security," "Two-step verification," or "Two-factor authentication."

The two tools I recommend

Authy, from Twilio. It's a free app for your phone that makes those six-digit codes. It's simple and clearly labeled, and it can back up your codes so you don't lose everything if you get a new phone. If you just want the second lock and nothing else, start here.

1Password. This is a password manager. It remembers all your passwords for you, fills them in when you log in, and can also hold your six-digit codes. It costs a few dollars a month, and the family plan lets a son or daughter help manage things. If the password book is getting messy, 1Password is the upgrade.

You can use either one. Or keep your password book and use Authy for the codes. That combination alone puts you ahead of most people.

Three habits that keep you safe

  • Never read a code to someone who calls you. Your bank will never ask for it. Hang up and call the number on the back of your card.
  • Don't click links in surprise emails or texts. Go to the website yourself.
  • When in doubt, ask someone you trust before you act. Scammers count on you hurrying.

The bottom line

Write your passwords down if that helps you. Use a different one for each account. And turn on the second lock (multi-factor authentication) for your email, your bank, and anywhere your money lives.

That one change does more to keep your data safe than any password ever will.

Andy Halvorsen helps small businesses and families stay safe with technology through AWH Industries.