Skip to content
Back to course

2. Strong passwords and password managers

Welcome to Lesson 2! In this lesson you will learn what makes a password strong or weak, why reusing passwords is dangerous, how to turn on two-factor authentication (2FA) for an extra layer of security, and how a password manager can remember everything for you. These habits are your single most important defence against account theft.

Your password is the key to your digital life. Every account — your TeleBirr, your bank app, your Gmail, your Facebook, your Telegram — is protected by a password. If a criminal gets your password, they can log in as you, steal your money, read your private messages, or lock you out completely.

The bad news: most people choose passwords that are very easy to guess. Studies consistently show that the most common passwords in the world are:

• 123456

• password

• 12345678

• qwerty

• 111111

Criminals know these lists. Automated tools can try thousands of common passwords in a few seconds. If your password is on any popular list, your account can be broken into almost instantly.

The good news: creating a truly strong password takes only a minute — and doing it right means your account becomes very hard to attack.

A strong password has four qualities:

1. Long — at least 12 characters. Length is the single most important factor. Every extra character multiplies how hard it is to guess.

2. Mixed — uses uppercase letters (A-Z), lowercase letters (a-z), numbers (0-9), and symbols (@ # $ ! %).

3. Random — not a real word, your name, your birthday, or your phone number. Criminals try personal details first.

4. Unique — used for only one account. Never reuse the same password on two different sites or apps.

A passphrase is an easy trick to get all four qualities at once. Choose three or four unrelated words and join them with a number or symbol:

Example: Coffee#Goat74Lion!

This password is 18 characters long, has uppercase and lowercase letters, a number, and a symbol — but it is still readable. A computer trying to guess it randomly would take millions of years.

Avoid: your name (Abebe2024), your phone number (0911234567), your city (AddisAbeba), or simple patterns (abc123, 1234qwer).

Danger of reusing passwords: Almaz uses the same password for her Facebook, Gmail, and CBE Birr app. One day, a small shopping website she had joined was hacked and her email and password were stolen. Because she reused the same password everywhere, the criminals immediately tried it on Gmail — they got in. Then on CBE Birr — they got in. A single breach became three breaches. This is called a credential stuffing attack, and it is extremely common.

Two-factor authentication (2FA) adds a second lock to your account. Even if a criminal steals your password, they still cannot get in without the second factor.

Think of it like this: your house key lets you open the front door. But imagine you also needed a fingerprint on a separate pad — a thief who stole only your key still cannot enter.

The three common factors are:

• Something you know — your password or PIN.

• Something you have — your phone (receives a one-time code via SMS or an authenticator app).

• Something you are — your fingerprint or face (biometrics).

2FA on most Ethiopian apps works by sending a 6-digit One-Time Password (OTP) to your registered phone number by SMS. Every time you log in from a new device, you enter both your password and the OTP.

How to enable 2FA:

1. Open the app settings (TeleBirr, Gmail, Facebook, Telegram, etc.).

2. Look for "Security" or "Privacy" settings.

3. Turn on "Two-step verification" or "Two-factor authentication."

4. Follow the instructions — usually entering your phone number.

Do it now for at least your email and mobile money accounts. It takes two minutes and dramatically reduces your risk.

Important: your OTP code is also secret. Never share it with anyone — not even someone who calls and claims to be from TeleBirr, your bank, or Ethio Telecom support. A real support agent will never ask for your OTP. If someone calls and urgently asks for the code that "just arrived" on your phone, hang up — it is a scam.

How can you possibly remember a different, 16-character random password for every account? The answer is: you do not have to. That is what a password manager does.

A password manager is a secure app that:

• Stores all your passwords in an encrypted vault — only you can unlock it.

• Generates strong random passwords for you — one click.

• Fills in passwords automatically when you open an app or website.

• Works across your phone and computer.

• Requires only ONE strong master password (and 2FA) to access everything.

You only need to remember one password — your master password — and the manager handles the rest.

Popular, trusted password managers:

• Bitwarden — free and open-source; works on Android, iPhone, and browser.

• Google Password Manager — built into Chrome and Android; free and easy.

• Apple iCloud Keychain — built into iPhone/iPad; free.

• 1Password — paid, but very polished.

For most people in Ethiopia using an Android phone, Google Password Manager is the simplest starting point because it is already on your device.

Your passwords are stored encrypted — even if the password manager company is hacked, attackers cannot read them without your master password.

Scenario

Abebe has one password he uses everywhere: "Abebe1990!" — his name and birth year. His brother knows it. He wrote it on a sticky note on his desk. What is Abebe's BIGGEST security problem?

Lesson recap: • A strong password is long (12+ characters), mixed (letters, numbers, symbols), random (not personal info), and unique (one password per account). • A passphrase — three or four unrelated words joined with numbers or symbols — is easy to remember and hard to guess. • Never reuse the same password across different accounts or apps. • Two-factor authentication (2FA) adds a second lock: even if your password is stolen, the attacker still cannot get in. • A password manager (Bitwarden, Google Password Manager) remembers all your passwords securely — you only need one strong master password. • Never share your password or OTP with anyone, even someone claiming to be from TeleBirr or your bank.

Check your understanding

1/7 · 80 XP

Which of the following is the STRONGEST password?