Reuse Is the Real Risk
How does a breach at a site you forgot about reach your bank?
The idea
A reused password turns any one site's breach into access to every account sharing it.
In the real world
A forum breach from years ago is replayed against email and banking.
Going deeper
Password strength resists guessing. A breach does not guess โ it hands the password over โ so complexity does nothing for the failure mode that actually causes most account takeovers.
What limits the damage is uniqueness. One strong password used everywhere means a single forgotten forum's breach unlocks email, and email unlocks everything through password resets. Mediocre but distinct passwords outperform one excellent shared one, which is why a password manager is the highest-value security change available to most people: it makes uniqueness practical.
Where it stops applying
Uniqueness matters most for accounts that gate others, particularly email. Perfect hygiene across every trivial account is not worth the effort it costs.
Why it matters
It identifies the single change that removes most of an ordinary person's exposure.
Try this today
Change the password on your email account to one used nowhere else.
Test yourself
Someone uses a strong 16-character password everywhere. Why is that weaker than mediocre passwords that are all different?
Show the answer
Strength resists guessing, and a breach does not guess โ it hands over the password. One compromised site then unlocks everything reusing it, so uniqueness is what limits the blast radius, and complexity does nothing for this failure mode.
Learn this in the feed Answering from memory, then again days later, is what makes it stick.