Passwords
What Should a Secure Password Look Like?
The most important characteristics of a secure password are length (number of characters) and complexity (number of character types: lowercase letters, uppercase letters, numbers, special characters). The BSI (German Federal Office for Information Security) recommends:
- 20–25 characters using two character types
- 8–12 characters using all four character types
- 8 characters using three character types when 2FA (two-factor authentication) is used
In addition, a password should not consist of things that are easy to guess, such as your child’s year of birth, your pet’s name, or other words from the dictionary. However, it is possible to use 5–7 randomly selected words separated by, for example, spaces, hyphens (-), or underscores (_).
Example:
Blaubeere-Saft-Konzentrat-Gerade-Oligarchie-Fahrenheit
In case a service provider becomes the victim of a data breach, different passwords should be used for each account. (A data breach is a security incident in which confidential or personal data unintentionally becomes accessible to unauthorized third parties.)
How Can I Make My Account Even More Secure? Should I Change My Password Regularly?
It is no longer recommended to change your password regularly. Doing so can encourage people to choose simpler, easier-to-guess passwords. However, if a service provider becomes the victim of a data breach, the password should be changed once. Changing a password can also be a good idea if it is found to be insecure or is used frequently across multiple accounts.
Instead, it is more advisable to use 2FA or to eliminate passwords altogether by using a passkey.
What Is Two-Factor Authentication (2FA) or Multi-Factor Authentication (MFA)*?
Authentication simply means proving to a service provider, when logging in, that the specified account actually belongs to you. This is done using the following authentication factors:
- Possession (e.g., a code on your phone)
- Knowledge (e.g., a PIN or password)
- Biometrics (e.g., a fingerprint)
With 2FA, two of these factors are used. For example, you enter a password (knowledge) and scan your fingerprint (biometrics).
*Two-factor authentication (2FA) is a subcategory of MFA, while MFA is not limited to only two steps. Organizations can require three or more factors for stronger protection.
What Is a Passkey?
The term refers to a way of authenticating without using a password. The device you use to log in stores a private key that belongs to a public key held by the service provider. Once passkey authentication has been set up, a fingerprint scan, for example, can be used. This covers at least two factors (in this case, possession and biometrics).
It is possible to create physical security backups or synchronize keys with the cloud to protect yourself in case the key is lost.
Unfortunately, not many services currently offer the option of setting up passkeys.
How Do I Use Passkeys?
To set up passkeys for authentication, you need an authenticator (attention: do not confuse this with authenticator apps; see “What Are Authenticator Apps?” below). This can be a so-called hardware token, such as a FIDO2 security key. In this case, you use a USB device that handles the generation and storage of passkeys.
Alternatively, you can use software. Which software you need depends on the operating system you use. The Verbraucherzentrale NRW (Consumer Advice Centre North Rhine-Westphalia) has compiled the following comparison:
| Operating system/manufacturer | Authenticator module | Storage location | Backup | Synchronization between multiple devices? | Can it be used with systems from other manufacturers? |
|---|---|---|---|---|---|
| Apple | iCloud Keychain | Cloud | iCloud Keychain | Yes | Yes |
| Google (Android) | Google Password Manager | Cloud | Google Password Manager | Yes | Yes |
| Windows | TPM (secure hardware module of the device) | Local | Password as fallback solution, FIDO2 security key | No | Yes |
Verbraucherzentrale NRW, article dated April 25, 2024, accessed May 28, 2025
What Can I Do to Remember My Passwords?
Passwords should not be written down in an unencrypted form, either physically or digitally. It is advisable to use a password manager (e.g., KeePass, NordPass). A password manager not only allows you to securely store passwords in encrypted form, but can also alert you to duplicate or insecure passwords, for example. It also includes an integrated password generator.
There are also various ways to make individual passwords easier to remember. For example, you can think of a long sentence and use the first letters of the words and the punctuation marks as the password.
Example:
Netzmelden ist eine innovative Plattform des youthprotect e.V., die sich dem Schutz und der Unterstützung von jungen Menschen im digitalen Raum widmet
→ NieiPdyeV,dsdSudUvjMidRw.
You can then replace a few letters with numbers (here, e → 3, i → 1).
→ N131Pdy3V,dsdSudUvjM1dRw.
What Are Authenticator Apps and Which Ones Are Available?
Authenticator apps can be used to make your account even more secure. After entering your password, you open an app on, for example, your phone, where a code is displayed for each registered service provider. This code is regularly updated. To use this feature, you first need to set up your account with the respective service provider. You will receive a QR code to scan or a numerical code to enter manually.
This means you are not only relying on the knowledge factor (password), but also on the possession factor (phone). As a rule, the app also allows you to create backups to protect yourself in case you lose your device.
We recommend one of the following authenticator apps:
Microsoft Authenticator
| + | - |
|---|---|
| No separate account required — although you can use your Microsoft account | No support for wearables |
| Integrated password manager |
Google Authenticator
| + | - |
|---|---|
| Supported by a very large number of service providers | Backups are cumbersome |
| No account required — but can manage multiple Google accounts | Collects a lot of data |
| Security is questionable — security vulnerabilities became known in 2020 | |
| Very short codes |
Stratum
| + | - |
|---|---|
| Can be used offline | Android only |
| Very simple backups | |
| Does not collect any data |
Authy
| + | - |
|---|---|
| Supported by a very large number of service providers | Transferring tokens (codes provided by the service provider) is cumbersome |
| Can also be used on a PC | |
| Can be used on multiple devices |
I Can't Remember My Passwords! What Can I Do?
In these cases, a password manager is useful. You can enter all the passwords you use into it. A so-called master password protects the entries and stores them in encrypted form.
Browsers offer the option of saving passwords. However, this feature should not be used, as passwords are often stored either unencrypted or with inadequate encryption. In the worst case, malware or hackers could extract them with relatively little effort.
We recommend one of the following password managers:
NordPass
| + | - |
|---|---|
| Easy to use | No local backups |
| Very secure | Expensive — the free version is rather limited |
| Android/iOS version collects data |
KeePass
| + | - |
|---|---|
| Free, with a very good range of features | Passwords are not checked for security |
| Synchronization across multiple password sources | Difficult for beginners |
| Supports security keys, passkeys, and 2FA |
Bitwarden
| + | - |
|---|---|
| Good free version | Password sharing is insecure |
| Easy to use |
Proton Pass
| + | - |
|---|---|
| Centralized device management | Expensive — with some missing features (e.g., synchronization across multiple password sources, duplication) |
| Supports security keys, passkeys, and 2FA |