ITIT Lunchroom
MFA, Passwords, and Account Safety

Passwords and Password Managers

Learn why using the same password everywhere is risky, how a password manager keeps each one safe for you, and where your passwords should and shouldn't be kept.

Keep each password in your password manager, and never share one or jot it on a sticky note.

Last reviewed 2026-06-17 by the IT Lunchroom Editorial Team. General guidance, not professional security or legal advice.

What you will learn

I can keep my passwords in a safe place without sharing them, reusing them, or leaving them somewhere risky.

You walk away able to give each account its own strong password, keep them in a password manager instead of scattered notes, and spot when a request for your password is a moment to stop.

password reuse and credential stuffingwhat a password manager doesunique long passphrasessafe credential storagewhy passwords are never shared

What a password manager actually does

A password manager is a safe, locked place that keeps all your passwords and types them in for you. It scrambles them so no one else can read them. You open it with one strong password — the only one you have to remember — and it looks after the rest. Because it remembers every login, you don't have to think them up or recall them yourself. That makes it easy to give each account its own long password, like a few plain words strung together (blue-river-lantern), which is easy for you to remember but hard for anyone to guess.

Why using one password everywhere is the real risk

Using the same password in lots of places means one leaked login can open many of your accounts. When any site you use gets broken into, criminals grab the leaked email-and-password pairs and quietly try them on other sites to see what else opens. Giving each account its own password keeps the trouble to just the one account that leaked.

Where your passwords should and shouldn't live

Your passwords belong only in a password manager, never in casual spots. Steer clear of sticky notes, spreadsheets, plain documents, chat messages, half-written emails, or your browser's saved list. Those places are easy for other people to read, get copied or shared by accident, and aren't built to keep a secret the way a password manager is.

Warning signs that a request isn't safe

Treat any request to tell, send, or share a password as a warning sign. Real help-desk and tech staff never need your actual password to help you, and no honest coworker needs to borrow your login. If someone pushes you to share a password fast, type it into a page you weren't expecting, or paste it into a message, that's your cue to stop and check with whoever handles tech where you are.

A simple routine to reuse anywhere

Keep it simple: give every account its own long password, save it only in your password manager, and never share it or reuse it elsewhere. If someone asks you for a password, or you're tempted to scribble one on a note, pause and check with whoever handles tech where you are before you do anything.

A worked example

Say a coworker messages that they're locked out and asks you to send the password for a tool you both use so they can get in. The safe move is to not send it, because passwords are never shared, even with teammates. Instead, point them to the normal way to reset a password or ask for their own access, and flag the message to whoever handles tech if it feels off.

Practice and evidence

Optional practice lets you rehearse picking a strong password and deciding where it belongs, using pretend logins, without touching a real account.

You write a short note describing how you make a different password for each account, where you keep them, and how you'd answer someone asking for your password, without ever writing a real password in it.

Common questions

Why is reusing the same password across accounts risky?

One leaked login can open many of your accounts. Attackers reuse leaked email-and-password pairs on other sites, so a unique password per account limits the damage to one place.

Where should your work passwords be stored?

Only in your password manager. A password manager is built to keep a secret, while casual notes are easy for others to read, copy, or share by accident.

Someone from support asks you to tell them your password so they can fix your account. What is the safest response?

Don't share it, because real help-desk staff don't need your actual password. Real help-desk staff can help without your password, so being asked for it is a reason to stop and check.

What should you do if a coworker is locked out of a shared tool and messages you to send over your password so they can get back in?

Don't send the password, and point the coworker to the normal way to reset a password or ask for their own access so they get their own login. Passwords are never shared, even with teammates you trust, because the safe way is for each person to have their own access.

What should you do if you just created a strong new password for a work account and need to make sure you do not forget it?

Save it only in your password manager, so it's kept safe and typed in for you next time. A password manager is built to keep passwords safe, while casual notes can be read, copied, or shared by accident.

Make it stick

Do the hands-on version of this lesson, then create a free account to save your progress. Finish a whole track and you earn a shareable certificate you can add to a résumé or job application. No payment, no catch.