Mom's 'pet name + birth year' passwords vs. my 20-character random mess, which one actually keeps us safer?
I was at my parents' house in Boise two weekends ago and watched my mom type her email password in front of me without a care, it was literally our old dog's name plus 1962. I told her that is the kind of thing hackers guess in seconds, and she said fine, but she can remember it, unlike the 20-character random string I made her try 6 months ago that she wrote on a sticky note under the keyboard. So now I am stuck. One side of me says long random passwords with a manager are the only real answer, because reused pet names show up in every breach dump and credential stuffing tools just chew through them. The other side says a password that lives on a sticky note under a keyboard is still safer than a 'strong' one she resets every 3 weeks and then writes in her phone notes anyway. I set her up with a manager and a YubiKey for her bank, and she still locked herself out twice. At what point does good security advice just make people less safe in practice? Anyone got a setup that actually works for a 70 year old who refuses to learn new tricks?