What this is about

Five situations around passwords. You never type a real password here — you only choose between examples.

What you practise

Recognise good passwords, use a separate one for every account and read the password manager as a warning sign.

Exercise

The interactive exercise needs JavaScript. Without it, you can read through all messages with their explanations here.

Two passwords to compare

A: Summer2025!

B: candle puffin hailstorm

Both are only examples — now that they're printed here, they're no good for anyone.

Which password is stronger?

  • ✓ B — three random words. – Exactly. Three random words make a password that's long enough and still easy to remember — that's the NCSC's advice.
  • ✗ A — it has a number and a symbol. – A word, a year, an exclamation mark: that hardly makes it stronger. It stays short and easy to guess.
  • ✗ Both are equally good. – B is much longer — and length makes guessing far harder.

Length beats symbols: three random words give you a long password you can remember. What matters is that the words really are random — not a line from a song, not a family name.

A data breach

An online shop announces that customers' passwords were stolen in an attack.

Your password there is the same as for your email and your Flickerhaven account.

What matters now?

  • ✓ Change the password everywhere you use it — and use a separate one for each account from now on. – Exactly. Criminals automatically try a stolen password on many other sites. Start with your email — it can be used to reset your other passwords.
  • ✗ Change it at the online shop only. – That's not enough: the same password also opens your email and Flickerhaven. Change it everywhere.
  • ✗ Do nothing — the shop will deal with it. – The shop can only protect its own account. Your other accounts with the same password stay open until you change it.

One password for everything is like one key for your house, car and safe: lose it and everything is open. A separate password for each account — a password manager remembers them for you.

Kestrelmoor Bank Online Banking

https://kestrelmoor-security.example/sign-in

Please sign in to confirm your account.

You got here through a link in an email. Your password manager has your Kestrelmoor login saved — and suggests nothing here.

What do you do?

  • ✓ Get suspicious: the address isn't kestrelmoorbank.example. Close the page and open the bank from your bookmark. – Exactly. A password manager only fills in your password on the correct website. If it stays silent, the address is wrong — this one belongs to kestrelmoor-security.example.
  • ✗ Copy the password from the manager and paste it in by hand. – That would be the mistake: the manager was right. It knows the real address — and this is a different one.
  • ✗ Type the password from memory. – Then the scammers would have it. If the manager suggests nothing, that's a warning sign — not a reason to try by hand.

A trap: a copied sign-in page. A password manager only fills in your details on the address it saved them for. If it stays silent, that's a warning sign — not a fault in the manager.

Kestrelmoor Bank Online Banking

https://kestrelmoorbank.example/online-banking/sign-in

You opened the page from your bookmark.

What do you do?

  • ✓ Let it fill in and sign in. – Good. Bookmark, correct address, and the manager offers the matching login — that's how it should be.
  • ✗ Cancel — password managers aren't safe. – On your own devices, a password manager is far better than a note or the same password everywhere. Here it recognised the right address.

Genuine. You opened the page yourself, the address ends in kestrelmoorbank.example, and the password manager recognises it. Nothing here speaks against signing in.

How strong is your password? Test it free!

https://password-strength-instant.test/

Type in your password — we'll tell you in seconds how secure it is.

You'd like to know whether your banking password is good. What do you do?

  • ✓ Don't type it in. A real password belongs only on the real sign-in page. – Exactly. Whatever you type on a stranger's site can be stored there. Whether a password is good depends on its length and on it being used for one account only.
  • ✗ Type it in — it's only a test. – Then the site knows your real password — and perhaps what you use it for. You only type a password where you sign in.
  • ✗ Type in a similar password, slightly changed. – That gives a lot away too: the real password can often be guessed from a similar one.

A trap — or at least a needless risk: you only type a real password on the real sign-in page. A good one is long, random and used for that one account only.

What makes a good password

Three random words

Three random words make a password that is long enough and that you can remember. Swapping letters for numbers or adding an exclamation mark hardly helps; family or pet names and dates don't belong in a password.

One per account

If one password leaks, it shouldn't open anything else. Your email above all deserves a strong, separate password — it can be used to reset all the others.

Let a manager remember

A password manager stores your passwords, creates new ones and only fills them in on the correct website. Saving passwords in the browser or phone is fine on your own devices — not on shared ones.

Passkeys where you can

Where a site offers a passkey, the NCSC now recommends it instead of a password. More at the next station.

Only on the real sign-in page

Never tell anyone your password — not on the phone, not in a message, not on a “password checker”. No genuine company asks for it.

To do at home

Ticks are just for now — nothing is saved.

Sources (checked 1 October 2026)

NCSC, Three random words, Managing your passwords (updated 21 May 2026), Use a strong and separate password for your email and Leave passwords in the past — passkeys are the future (23 April 2026).

All companies, people, addresses and numbers in the exercises are invented. Any resemblance to real companies or people would be purely coincidental and unintended.

An unhandled error has occurred. Reload 🗙

Rejoining the server…

Rejoin failed… trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.