Lesson 2 of 7
Password Security
Discover how attackers crack credentials, why passphrases beat simple passwords, and how MFA guards your accounts.
Learn it
Think of a password as the secret key to your personal digital treasure chest. If someone guesses your password, they can read your emails, delete your game saves, or pretend to be you.
Short passwords like '123456' or 'qwerty' can be cracked by a computer in less than a single second. Strong passwords are long, use a mix of symbols, numbers, and letters, or combine several unrelated words into a passphrase like 'Rocket-Toaster-Velvet-99'.
Never use the exact same password for two different accounts. If one service gets hacked, attackers will try that same password on all your other accounts!
Key terms
- Brute-Force Attack
- A trial-and-error method where automated software tries every possible combination of characters until it finds the password.
- Dictionary Attack
- A technique that attempts to break in using a targeted list of common words, phrases, and previously leaked passwords.
- Multi-Factor Authentication (MFA)
- A security system requiring two or more distinct pieces of evidence to verify a user identity before granting access.
- Passphrase
- A sequence of multiple words or characters strung together to form a long, memorable, and high-entropy credential.
Creating an Unbreakable Passphrase
Learn the four-word passphrase technique recommended by top cybersecurity agencies around the world.
- 1Pick Four Random Words: Choose four distinct, unrelated nouns (for instance: Falcon, Waffle, Sunset, Blanket).
- 2Add Separators: Link the words together using dashes, underscores, or special symbols (e.g. Falcon-Waffle-Sunset-Blanket).
- 3Inject Numbers and Cases: Capitalise specific letters and insert a couple of random numbers (e.g. Falcon-Waffle7-Sunset-Blanket!).
- 4Enable Multi-Factor Authentication: Pair your new passphrase with an authenticator app to lock down your account.
Password Strength Validator
pythondef check_strength(password):
length_ok = len(password) >= 12
has_digit = any(char.isdigit() for char in password)
has_special = any(not char.isalnum() for char in password)
if length_ok and has_digit and has_special:
return 'Strong Password'
return 'Weak: Needs 12+ chars, numbers, and symbols'This Python function evaluates whether a proposed password meets three essential criteria: a minimum length of 12 characters, at least one numerical digit, and at least one special symbol.
Try it
Complete the code to verify that a user password is at least 14 characters long.
def is_secure_length(password):
# Return True if the length meets the minimum threshold
return ______(password) >= 14Challenge
Design a password policy for an online bank. List the minimum length, character requirements, and renewal rules.
Pick whichever way suits you — every mode earns the same bonus XP.
Write at least 40 more characters to submit.
Mark your own work
Guided walkthrough — 0/5 clues revealed
- Clue 1 locked — reveal it only if you get stuck.
- Clue 2 locked — reveal it only if you get stuck.
- Clue 3 locked — reveal it only if you get stuck.
- Clue 4 locked — reveal it only if you get stuck.
- Clue 5 locked — reveal it only if you get stuck.
Each clue costs 3 XP (never below 15 XP). You'd earn 30 XP right now.
Extension: Explain how a password manager stores credentials safely using master encryption keys.