Here is the liberating secret the password industry buries: you only need to memorize two passwords — your email and your manager master. Everything else gets generated, stored and autofilled. People who try memorizing twenty unique secrets fail into reuse; people who memorize two passphrases properly succeed permanently. This is how to remember passwords without reusing a single one.
Part of the password generator guide. Build masters with the passphrase tool; bulk-generate the rest in the generator; verify ratings in the strength tester.
The two-secret system (memorize this, automate the rest)
- Email passphrase (5 words): your inbox resets everything else, so it earns a master-grade secret. Memorize via story method below; enable app-2FA the same day.
- Manager master (5–6 words): the vault key. Never stored anywhere except your head (+ sealed paper backup with a trusted person or safe).
- Everything else (200+ logins): random 16+ strings, generated per site, autofilled by the manager. Zero memory allocated, ever. Practice passphrase mechanics with the passphrase tool; build real masters from full-size wordlists (physical dice) or 20+ character generator secrets.
Onboarding order matters: email first (resets depend on it), manager second, bank third, then migrate accounts in weekly batches of ten — not a heroic weekend that burns out at forty. New accounts get generated secrets from birth; no legacy exceptions.
The story method (memorize 5 words in 10 minutes)
Random words stick when embedded in one absurd mental movie. Example draw — “candle, tractor, violet, orbit, seven”: picture a candle balanced on a tractor painted violet, launching into orbit past seven moons. Rehearse the movie (not the list) at 1 hour, 1 day, 1 week — spaced repetition locks it. Absurdity is the glue: boring images fade, bizarre ones persist for years. Type the passphrase 20 times during setup week; fingers learn what brains rehearse. Never use the story words as answers to “security questions” anywhere — and better, never use security questions at all (NIST retired them; use MFA recovery codes stored offline).
No manager yet? The bridge routine
- Paper vault, temporary: write generated passwords in a notebook kept at home — vastly better than reuse while you adopt a manager. Never photograph it, never carry it routinely.
- Priority migration: email, bank, UPI-linked accounts and work logins move to generated+managed first; forums and newsletters last.
- Never: browser-only saving as the sole store (convenient, syncs to accounts attackers phish), plaintext phone notes, or “encrypted” Word docs with guessable passwords.
- Deadline yourself: 30 days to full manager adoption. Bridge routines calcify into permanent bad habits without a date — schedule the migration Sundays.
Design recovery before you need it (the forgotten half)
Every memorization plan needs a forgetting plan. For each master secret, record: sealed paper copy location (safe, trusted person — never photographed), MFA recovery codes alongside it, and the service's account-recovery path tested once (actually run a test recovery on a secondary account to learn the flow). Review yearly: paper still sealed and locatable, codes current after MFA changes, trusted person still trusted. The nightmare scenario — lost master plus lost codes — is unrecoverable by design; fifteen minutes of recovery design today prevents it permanently. Treat recovery artifacts with master-level secrecy: anyone holding them holds everything.
General information only, not security advice. Generate offline, store in a manager, enable MFA on email/bank. If you lose your master password it cannot be recovered by us.