Password security library
Understand password length, reuse, breach response, hashing, recovery and the attacks that turn one exposed credential into many compromised accounts.
How to use this section
Use the Password security library directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.
What belongs in this section
Begin with the issue that creates the largest blast radius: a compromised primary email, reused password or weak recovery path. Concept pages are useful only when they lead to a specific change or monitoring decision.
Brute-Force vs Dictionary Password Attacks
Compare exhaustive guessing, wordlists, rules and online rate limits.
Open guide →Credential Stuffing Explained
Understand how attackers reuse exposed username-password pairs and how unique credentials stop the chain.
Open guide →How Long Should a Password Be?
Understand practical password length recommendations, NIST guidance and why length must be combined with uniqueness and randomness.
Open guide →How to Check for Account Takeover
Review sessions, recovery changes, messages, transactions and connected apps after a suspicious alert.
Open guide →How to Create a Strong Master Password
Build a unique master passphrase that is long, memorable and protected with multifactor authentication.
Open guide →Password Hashing vs Encryption
Understand why passwords should be verified with slow hashes rather than stored with reversible encryption.
Open guide →Password Security Checklist
Audit passwords, recovery methods, multifactor authentication, devices and breach response with a practical checklist.
Open guide →Password Spraying Explained
Learn how attackers test a few common passwords across many accounts and how organizations can respond.
Open guide →Password vs Passphrase: Which Is Better?
Compare random passwords and passphrases for password managers, master passwords, Wi-Fi and everyday accounts.
Open guide →Password Salts and Peppers Explained
Learn how unique salts and separately protected peppers strengthen password-hash storage.
Open guide →Secrets Management Basics
Protect API keys, tokens, certificates and passwords across creation, storage, use and rotation.
Open guide →How Secure Password Reset Links Should Work
Understand one-time tokens, expiration, HTTPS and user-notification practices.
Open guide →What to Do After a Data Breach
Follow a prioritized response plan after a service reports exposed account information or you suspect credential theft.
Open guide →Why Password Reuse Is Dangerous
Understand credential stuffing, password reuse risk and how to move to unique passwords without losing access.
Open guide →Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.