One password, every door
Essentials plan
One reused password opens every account once it leaks. See how attackers do it, then switch to a password manager, passkeys and MFA.
- 2 min
- 4-question check
- English · Français
- Attestation
You will be able to
- Explain credential stuffing and why one reused password opens every account
- Use one unique password per site with a password manager
- Prefer passkeys or multi-factor authentication
- React to a leak: change the password everywhere and tell IT
The module
2 min-
One password, every door 2 min
-
Knowledge check
4 questions, pass mark 80 %. Explanations after each answer; you can try again.
-
Attestation
One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.
Sources
- Verizon, 2025 DBIR — credential stuffing research (median: 49 % of a user's passwords are distinct)
- NIST SP 800-63B-4, July 2025 (no forced periodic change, no composition rules, password managers allowed)
Version 1 · updated October 2, 2026