One password, every door

Essentials plan

One reused password opens every account once it leaks. See how attackers do it, then switch to a password manager, passkeys and MFA.

  • 2 min
  • 4-question check
  • English · Français
  • Attestation

You will be able to

  • Explain credential stuffing and why one reused password opens every account
  • Use one unique password per site with a password manager
  • Prefer passkeys or multi-factor authentication
  • React to a leak: change the password everywhere and tell IT

The module

2 min
  1. One password, every door 2 min
  2. Knowledge check

    4 questions, pass mark 80 %. Explanations after each answer; you can try again.

  3. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Sources
  • Verizon, 2025 DBIR — credential stuffing research (median: 49 % of a user's passwords are distinct)
  • NIST SP 800-63B-4, July 2025 (no forced periodic change, no composition rules, password managers allowed)

Version 1 · updated October 2, 2026