Choose four to six uncommon words, weave a personal association, and sprinkle meaningful separators to resist dictionary attacks without sacrificing memory. Avoid famous quotes, song lyrics, and predictable patterns. Test for breaches, rotate only when needed, and record recovery hints safely outside inboxes.
A good vault reduces friction, not freedom. Start with device-based encryption, a memorable master passphrase, and hardware key support. Disable autofill on unknown sites, enable biometric unlock carefully, set emergency access for trusted partners, and export an encrypted backup you verify quarterly without fail.
Adopt app-based codes or hardware security keys for your most important accounts, reserving SMS for last resort recovery only. Store backup codes offline, enroll at least two factors per account, and practice one clean re-enrollment so downtime never meets a locked door.