Skip to content
Safety & Privacy

Creating Strong Passwords

Back to Security Center

Your safety guides how we build. Read this at your own pace, and reach our team any time from the Security Center.

Why Weak Passwords Fail

Every year, data breaches expose millions of passwords. The most commonly leaked passwords include predictable choices such as "123456", "password", and "qwerty". Attackers use automated tools that can test billions of combinations per second, meaning a short or simple password can be cracked in moments. If you reuse the same password across multiple accounts, a single breach can give criminals access to your email, social media, banking, and marketplace accounts all at once.

You can check whether your email address or passwords have appeared in known data breaches by visiting Have I Been Pwned, a free service run by security researcher Troy Hunt.

What Makes a Strong Password

A strong password has several characteristics that make it resistant to both automated attacks and educated guessing:

The Power of Passphrases

One of the most effective techniques for creating a strong yet memorable password is to use a passphrase. A passphrase is a sequence of random words strung together, such as "correct horse battery staple" or "umbrella triangle forest candle". Passphrases work well because they are long enough to resist brute-force attacks whilst remaining easier to remember than a random string of characters.

The National Cyber Security Centre (NCSC) recommends using three random words combined together as a practical approach to password creation. For example, "purpleMonkeyDishwasher" is far stronger than "P@ssw0rd!" because its length provides significantly more entropy.

Why You Need a Password Manager

Remembering a unique, complex password for every account is practically impossible without assistance. This is where password managers become essential. A password manager is a secure application that stores all your passwords in an encrypted vault, protected by a single master password. Popular options include Bitwarden, 1Password, and KeePass.

Benefits of using a password manager include:

One Password Per Account

Using the same password across multiple services is one of the most dangerous habits in digital life. When attackers obtain a list of leaked credentials from one service, they immediately try those same email and password combinations on other popular platforms. This technique, known as credential stuffing, is remarkably effective because so many people reuse passwords.

On KF.Social, your account protects your personal information, your marketplace transactions, and your social connections. If an attacker gains access using a password you also use elsewhere, they could impersonate you, make fraudulent purchases, or access private messages. Always use a distinct password for your KF.Social account.

Practical Steps to Improve Your Password Security Today

  1. Check your existing passwords against Have I Been Pwned to see if any have been exposed in a breach.
  2. Install a reputable password manager and begin migrating your accounts to strong, unique passwords.
  3. Start with your most critical accounts: email, banking, and social platforms such as KF.Social.
  4. Enable two-factor authentication wherever possible for an additional layer of protection.
  5. Set a strong master password for your password manager using the passphrase technique described above.

For more detailed guidance on password security, read the NCSC's password guidance. Taking a few minutes to strengthen your passwords now can save you significant trouble in the future.

Back to Security Center

Meet people, safely.

ID checks you can see, real dinners, and a team that has your back. See how it works.

KF.Social
Go for dinner. Leave with friends.
Get the app