top of page
Search

Password Security Check

Writer: Alex Potter, CFP®
Alex Potter, CFP®
Sep 2
4 min read


For this month’s blog post, I wanted to share the importance of having a secure password. In today’s world of advanced computers and AI, a strong password matters more than ever. Here are some tips and information along with some best practices you can implement today.


Password Length


Security firm Hive Systems publishes a table each year showing how fast hackers can crack a password. As you will see, the more you incorporate lowercase, uppercase, numbers and symbols, you can go from a password that can be hacked instantly to taking over a quintillion years. 



Easy password: hxKque - can be hacked within 2 days (6 characters with upper and lowercase letters). According to security.org this could be hacked in as little as a few milliseconds.


Difficult password: x0cQ3r! - would take a hacker up to 2 years (7 characters with numbers, upper and lowercase letters, and a symbol). Security.org says 6 minutes.


Strong password: Wq@tj3r! - 132 years to crack (8 characters with numbers, upper and lowercase, and a symbol). Security.org says 8 hours.


Unbreakable password: K-l0vq-$yrUw-*1 - a hacker would need to brute force attack for 1 quadrillion years to solve (15 characters with numbers, upper and lowercase, and a symbol). Security.org says 15 billion years.



*Hive uses a base case of hackers using 16 X RTX 5090 chips. A sophisticated hacker could use a much larger pool of chips to generate more “power” to increase hacking times. Security.org provides greater context on password strength at the extreme end. The bottom line... use a longer password of at least 15 characters of randomness. 



Get a Password Manager


If you are at all like me, it gets very challenging trying to remember 20+ passwords and then having to update them regularly. A password manager can help solve this. Apple and Google have free built-in password managers, and services like LastPass or Keeper offer password management as well. 


Multi-Factor Authentication (MFA)


This is perhaps the single biggest upgrade you can add to your accounts today. MFA protects your private information by adding an additional layer of security. After you enter your password, you also receive a code by text or phone call before logging in. Even if a hacker discovered your password, they wouldn’t have access to your phone.


Another option is a TOTP, or Time-Based One-Time Password. Download an authenticator app (Google or Microsoft Authenticator are the common ones) and link it to your account, usually by scanning a QR code. From then on, you log in with your password plus the 6-digit code in the app, which refreshes every 30 seconds. 





Device Checklist


iPhone:

  • Use a 6-digit or longer passcode (Settings ⟶ Face ID & Passcode).

  • Turn on Two-Factor for your Apple Account (Settings ⟶ Your Name ⟶ Sign-in & Security).

  • Let iCloud Keychain store your passwords; turn on automatic updates.


Android:

  • Set a 6+ digit PIN or password, not a swipe pattern.

  • Turn on 2-Step Verification at myaccount.google.com/security.

  • Use Google Password Manager, which can help flag reused or breached passwords.


Windows:

  • Use Windows Hello (fingerprint, face or PIN) under Settings ⟶ Accounts.

  • Add 2-Step Verification at account.microsoft.com/security 

  • Leave Windows Update and Defender on.


Mac:

  • Use a strong login password plus Touch ID.

  • Turn on FileVault encryption (System Settings ⟶ Privacy & Security)

  • Use the build-in Passwords app; keep macOS updating automatically.



The Real Threat... is YOU!


The most common way passwords are exposed is by handing them over! Be vigilant about suspicious emails, texts, and phone calls that create urgency to release passwords. Hackers will grab your attention with lines like “your account is locked”, “confirm this wire”, or “your grandson needs money”. Real institutions will never ask for passwords or codes out of the blue. 


Another common phishing method is an email that looks slightly off. For example, you may receive an email from John Smith, who you know and trust. His email address that you are familiar with is johnsmith@xyzbank.com, but the email is requesting personal information which raises red flags. After examining the email, you may notice the email address actually is john$mith@xyzbank.co. They look similar at first glance, but after careful inspection they are vastly different. 


This page has some useful information about phishing scams: Wikipedia Phishing Scam



Your One-Hour Homework


Take an hour out of your day to consider doing the following.


  • Update passwords to include random numbers, upper and lowercase letters and symbols. Aim for a minimum of 15 characters.

  • Turn on Multi-Factor Authentication for email, bank accounts, investment accounts, etc.

  • Set up a password manager.

  • Update your phone and computer software if needed.


By taking these proactive steps, the goal is to protect against the ever-increasing threat of hackers and scammers. 


If you’d like to set aside 30 minutes to walk through any of these security measures, schedule a time here: Security Check Meeting.


Have a wonderful month!



Alex Potter, CFP® 



Alex Potter, CFP®
Alex Potter, CFP®

Password Fact


The most common password is "123456" which continues to appear in millions of exposed and breached accounts.


Securities offered through Registered Representatives of Cambridge Investment Research, Inc., a Broker/Dealer, Member FINRA/SIPC. Investment Advisor Representative, Cambridge Investment Research Advisors, Inc., a Registered Investment Advisor. This communication is strictly intended for individuals residing in the states of MI, IN, OH. Cambridge and Foundation Wealth Management are not affiliated.


 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

FWM

Resources

Social

  • Facebook
  • LinkedIn

Securities offered through Registered Representatives of Cambridge Investment Research, Inc., a Broker/Dealer, Member FINRA/SIPC. Investment Advisor Representative, Cambridge Investment Research Advisors, Inc., a Registered Investment Advisor. Cambridge and Foundation Wealth Management are not affiliated. Financial Professionals may only conduct business with residents of the states of jurisdictions in which they are properly registered, licensed or exempt from registration and not all of the securities, products and services mentioned are available in every state or jurisdiction.

© 2025-2026 by Foundation Wealth Management, LLC

bottom of page