Help protect children from gaming harms.

Take our survey

Please or to access all these features

AIBU?

Share your dilemmas and get honest opinions from other Mumsnetters.

To be fed up of passwords for everything in life?

93 replies

doorbellringer2 · 28/07/2026 00:33

I am so sick of passwords/passcodes for everything in every day life. We are told we should have different, super strong passwords for every single thing.
Want to access your banking, mortgage, pension, insurance, supermarket loyalty scheme, hairdresser booking app, school app, kids club app? Then each of those should have their own unique random password. Something like P2d3&r#K@0 is often the suggested one. How are we supposed to remember each one?
I know my iPhone has a passkey thingy to remember them, but what if my phone gets lost or stolen? Apparently those are the first things they look to target, and if they get in to one of the accounts then they change the verification email addresses and it can lock you out of everything. Apparently it can take months to sort out. It’s so depressing.
This is triggered by recently being abroad and someone tried to hack my Revolut account. I had to block access and transfer my money to another account.
I believe you wouldn’t be covered by insurance if you wrote them down in a notebook and that was discovered by robbers and they could then access your stuff.
Does anyone else miss the simple days when you were not fighting off criminal masterminds daily?

OP posts:
Itsasecretnow · 28/07/2026 10:35

LongDistanceClara44 · 28/07/2026 10:12

So, inspired by this thread, I went on my Google password manager. It told me there were over 200 compromised passwords. I spend twenty minutes deleting them all. Now it turns out that solved nothing... the passwords are still the same for the websites. I think i just deleted my own prompt. And now because I deleted them I don't even know which ones are compromised. I think this means that now any hacker can easily get access but I probably no longer can as I deleted the only thing that was helping me to remember them. Brilliant...

It’s too late now, but what you should have done is gone into each site/app/whatever and changed your password on there and then accepted the prompt when it comes up from Google/icloud etc for them to save your new password.

However, it really isn’t too late tho, because you can go on to each app or site and do the “forgot password” option when you go to sign in. It’ll then usually send a link to phone or email which you can click on to take you back and choose a new password. Good idea to accept the secure password suggestion you usually get, and then it’ll save it for you. If available make the choice to sign in to relevant places with your biometrics if it’s offered.
yes, it’ll be slow as you have to do then one by one but you’d have had to likely have done it that way anyway, it will just take a little longer this way.

I hope this makes sense!?

LongDistanceClara44 · 28/07/2026 10:40

Itsasecretnow · 28/07/2026 10:35

It’s too late now, but what you should have done is gone into each site/app/whatever and changed your password on there and then accepted the prompt when it comes up from Google/icloud etc for them to save your new password.

However, it really isn’t too late tho, because you can go on to each app or site and do the “forgot password” option when you go to sign in. It’ll then usually send a link to phone or email which you can click on to take you back and choose a new password. Good idea to accept the secure password suggestion you usually get, and then it’ll save it for you. If available make the choice to sign in to relevant places with your biometrics if it’s offered.
yes, it’ll be slow as you have to do then one by one but you’d have had to likely have done it that way anyway, it will just take a little longer this way.

I hope this makes sense!?

Thank you very much for trying to help me. The problem is I don't remember what the sites were, some of them were for things I haven't logged into for ten years, that maybe I just had to set up a password to use the site once. Hopefully this means it doesn't matter too much

QuinionsRainbow · 28/07/2026 10:52

BT are my pet hate at the moment. Introduced mandatory 2 Factor Authorisation via mobile phone for all-mail log ins, And also demanded that we change our BT-ID from a simple phrase to an e-mail address format. The result. Most of our family e-mail addresses, tied to a single BT billing account are now only accessible via a single mobile number, which is inconvenient, to say the least. To add insult to injury, our myBT arrangement is now decoupled from our billing account, and it's impossible to log in to anything administrative. I spent over two hours with a BT chat-line agent trying to sort this last week,but no joy.
Cue angry letter to BT CEO! That worked for us last time we had a grievance over service.

Keepoffmyartichokes · 28/07/2026 10:52

Another vote here for Lastpass or similar. I use to to create the passwords so they are all random.
Worrying how many think it would be difficult to guess someone's password, in most cyber crime cases there isn't a person sat there manually trying passwords, they have scripts running trying thousands of different combinations. This is called a brute force attack, the shorter the password makes it easier for the software to crack. If you then have similar password combinations then it's incredibly easy for that hacker to guess.
Banks lose hundreds of thousands of pounds a year to Fraud this is why they and other companies are cracking down on simple passwords. It's not a case of it's up to you how safe it is, if you are hacked and lose money you will no doubt expect the bank to reimburse you and investigate the fraud.

Iwantanothergo · 28/07/2026 10:53

Iouko · 28/07/2026 00:40

Use a password manager like last pass or Bitwarden. I would be lost without Bitwarden!

I used to use LastPass but got fed up with not being able to use it on some sites. I now have my own system, where all my passwords are different but have a theme in common that lets me remember them.

Keepoffmyartichokes · 28/07/2026 10:54

Iwantanothergo · 28/07/2026 10:53

I used to use LastPass but got fed up with not being able to use it on some sites. I now have my own system, where all my passwords are different but have a theme in common that lets me remember them.

You can use lastpass for any site. It doesn't always auto fill the information for every site but you just log into lastpass and copy the login details over

SunnySunnyDayz · 28/07/2026 11:00

Agree entirely. And having to create an account for a one time purchase, or a site recognising your email and insisting you log in when trying to use the guest checkout.

Having said that, crypto is so much worse! There's no way to recover your password, if you forget it your tokens are locked up forever.

mondaytosunday · 28/07/2026 11:03

Password for obviously sensible things like finance/credit cards etc is sensible, but not sure why I need one for ordering off a website. If someone hacks my phone then they are probably good enough to get around a password to anything else. I don’t keep my payment cards on the website’s records.

FlapperFlamingo · 28/07/2026 11:05

i Use a password manager called Dashlane which gives me access to passwords across all my devices. Much easier and cuts the flaff. You can also more easily change passwords too.

TonTonMacoute · 28/07/2026 11:06

TheTortiePuffinNeedsHerBreakfast · 28/07/2026 04:22

I have resorted to keeping mine written down in a little book that I keep hidden at home. These days I think it's far less likely for someone to find your passwords if stored physically than digitally.

Can't be hacked!

However, they are adding new layers of complication with pass keys, biometric, one time codes, goodness knows what else. One day we will wake up and no one will be able to access anything at all.

duckydoo234 · 28/07/2026 11:23

FlorisApple · 28/07/2026 10:25

It's not just passwords either! It's: put your password in, then verrify it with an email/text, then authenticate it on your authenticator app. My God! will it be four-step verification soon? Ok, after you have done all that, you can order your child's lunch from the canteen 🙄Takes me so long to do anything?!

God yes. I'll sometimes use my laptop when I don't have my phone with me, and it sends a message to my phone to verify, when it could just ask for my password. So no can do without every device.

BowlingSunflowers · 28/07/2026 11:36

TrishM80 · 28/07/2026 04:02

Do you need a password for that?

For Bitwarden you need one password, mine is 20 characters long. This is like accessing a vault in a bank.

Bitwarden then holds all your passwords securely. We used to use LastPass but I can't remember why we changed. We have a family member who deals with IT security of sensitive data and listens to the latest podcasts on this sort of thing.

As you log onto accounts you can add them to Bitwarden. When you need to create a new password for an account Bitwarden will do it for you and you can dictate the length, you save this into Bitwarden.

Our Wifi password is 64 characters, there is no way I could remember that. We always have 2 factor authentication on everything too.

All you need to remember is that one password and Bitwarden does the rest. I have it on my phone installed as an app and on my desktop computer.

Wipeywipey · 28/07/2026 11:40

Keepoffmyartichokes · 28/07/2026 10:52

Another vote here for Lastpass or similar. I use to to create the passwords so they are all random.
Worrying how many think it would be difficult to guess someone's password, in most cyber crime cases there isn't a person sat there manually trying passwords, they have scripts running trying thousands of different combinations. This is called a brute force attack, the shorter the password makes it easier for the software to crack. If you then have similar password combinations then it's incredibly easy for that hacker to guess.
Banks lose hundreds of thousands of pounds a year to Fraud this is why they and other companies are cracking down on simple passwords. It's not a case of it's up to you how safe it is, if you are hacked and lose money you will no doubt expect the bank to reimburse you and investigate the fraud.

But banks are the ones who wanted to make everything secure in this format! My dad wouldn't be able to use his bank account he has had for 60 years without learning how to verify everything on a "blasted 'phone" as he calls it.

BashfulClam · 28/07/2026 11:47

LimeFish · 28/07/2026 10:34

This is very easy to hack though. If the criminal gets thr Netflix password yhrough a data breach with Netflix at the end they could easily figure out that trying it with Natwest at the end might be the Natwest password.

How would they know he had a NatWest account, how do they get his username?

Theunamedcat · 28/07/2026 11:50

My son has a managed mobile its supposed to be managed from my mobile but the app doesn't work on mine it wont tell me why it will work from his so I can log in and change settings unfortunately if I want to do anything really big like adding a previous banned app it wants to send a code to the "parents" phone and sends it JUST to my adult sons phone not my phone his brothers

His tablet is even better again managed restricted age 13 only etc etc but now apple have decided it must have apple pay or it will turn into a brick fucks sake I dont want my autistic child having access to my account

IDontHateRainbows · 28/07/2026 11:50

LindorDoubleChoc · 28/07/2026 05:41

YADNBU! I also hate it when you can't buy something online without creating an account (which will then spam you with emails daily). Whatever happened to the Continue As Guest optiin?

An even worse horror is the ones where you may be browsing and add to basket you then get bombarded with 'did you forgot to check out' type emails. no, I didn't FORGET to check out, i never do if I really want something, I just changed my mind (or more honestly, decided I couldn't afford it)

Excited101 · 28/07/2026 11:53

they don’t care a jot about what’s on your phone when they steal it- they wipe it and ship it off to china within days, so it’s not really an issue on that tbh.

but I agree with you, it’s absolutely ridiculous and I’m fairly sure now there’s so many- less secure. We’ve gone from carefully chosen safe passwords to ‘hairdresser1234’ as we’ve got too many to keep track of.

Iouko · 28/07/2026 11:56

BashfulClam · 28/07/2026 11:47

How would they know he had a NatWest account, how do they get his username?

If he uses that same format for his email without 2fa, you’d get into his email like that and start looking for emails that may have account info in. Or just skip the banking and they would try online shopping, until you find one with pre saved payment details etc and start ordering things.
if one password leaks you’re than having to change every single password.

Strawberry1975 · 28/07/2026 12:27

@BowlingSunflowers So would i need to really pick a new password , one ive not used before ? as so many say password leaked or would that not matter for the Bitwarden password.

Keepoffmyartichokes · 28/07/2026 13:09

Wipeywipey · 28/07/2026 11:40

But banks are the ones who wanted to make everything secure in this format! My dad wouldn't be able to use his bank account he has had for 60 years without learning how to verify everything on a "blasted 'phone" as he calls it.

Because it's banks who are paying out when customers get hacked because their passwords are rubbish and not secure. A lot it comes from regulators telling banks what to do rather than the banks themselves. They are not doing it to make your life difficult. I work for a bank, within Fraud.

BowlingSunflowers · 28/07/2026 18:00

@Strawberry1975 I would pick a new password. Easy things are song lyrics first letters, so The Beatles We Can Work It Out second verse

"Think of what you're saying
You can get it wrong and still you think that it's alright"

Use the T as the capital first letter or the Y as a capital but turn O into zero and an I into an exclamation point or a 1 becomes T0wysOycg!wasytt!a you could add a random number, hashtag, percentage or whatever in there too.

Obviously choose something less obvious than The Beatles but you get my point.

Wipeywipey · 28/07/2026 18:13

Keepoffmyartichokes · 28/07/2026 13:09

Because it's banks who are paying out when customers get hacked because their passwords are rubbish and not secure. A lot it comes from regulators telling banks what to do rather than the banks themselves. They are not doing it to make your life difficult. I work for a bank, within Fraud.

So you can tell us if the problems with fraud were as bad pre-password? I certainly don't remember it being an issue, ever, for my parents generation either. The daily assault on customers of fear that our money is at risk is because some guys in banks and insurance firms decided our money would be safer online. That threat is all largely post internet.

Netcurtainnelly · 28/07/2026 18:34

Yanbu.

NewYearVibes · 28/07/2026 18:39

Amiiee · 28/07/2026 00:52

No but they can't just crack a very strong password

But if the organisation has a leak and your password is within the leak, you'll have to change the password everywhere.

However, the days of passwords are numbered and it's not recommended anymore. You'll be asked for passkeys. It's going to get worse if you lose your phone.

NewYearVibes · 28/07/2026 18:40

Also, I have bitwarden. It's a subscription for the whole family. It's impossible to remember all passwords clearly.