Last reviewed: Next review due:
Why passwords matter for journalists
Journalists are high-value targets for account takeovers. A compromised email account exposes source communications, unpublished stories, and contact details. A compromised social media account can be used to spread disinformation, approach sources under false pretences, or destroy a journalistic reputation. Weak or reused passwords are the most common cause of account compromise — and they are entirely preventable.
A password manager generates a unique, random, strong password for every account. You only need to remember one master password. Combined with strong two-factor authentication (2FA), this makes account takeover extremely difficult for all but the most sophisticated attackers.
Password manager comparison
Commercial, cross-platform, excellent browser integration. Travel Mode lets you hide vaults when crossing borders. Journalist Safety Fund offers discounts. ~£3/month.
Open-source, free tier covers most needs, premium ~£10/year. Cloud-hosted by default; can self-host for maximum control. Independent audits conducted.
Free, open-source, vault stored locally — never on a cloud server. Requires manual sync between devices (e.g., via an encrypted USB or Syncthing). More technical setup but no cloud dependency.
2FA options ranked by strength
- 1 — Best: Hardware security key (YubiKey, Google Titan)
Phishing-resistant. Physical device required to authenticate. Cannot be intercepted remotely.
- 2 — Good: TOTP app (Authy, Google Authenticator, Aegis)
Time-based codes generated on your device. Phishable by sophisticated fake login pages but far better than SMS.
- 3 — Avoid if possible: SMS / phone call 2FA
Vulnerable to SIM-swap attacks. Only use if no better option is available. Never for your most critical accounts.
Red flags
- You reuse the same password on multiple accounts.
- Your passwords are stored in a spreadsheet or text file.
- You use SMS as your primary 2FA method on high-value accounts (email, cloud storage, social media).
- You have no 2FA enabled on any account.
- Your password manager master password is the same as another account password.
- You have not set up an offline backup of your vault in case you lose access.
Password & 2FA checklist
- I use a password manager for all accounts.
- Every account has a unique, manager-generated password.
- My password manager master password is long, unique, and memorised (not written on a sticky note).
- 2FA is enabled on all critical accounts: email, cloud storage, social media, bank.
- I use TOTP or a hardware key for 2FA — not SMS — on my most sensitive accounts.
- I have an offline backup of my password vault (exported and stored on an encrypted USB).
- I know the recovery procedure if I lose access to my 2FA device.
Source protection checklist
Account security is part of source protection. Check whether your setup is adequate.
Source Protection ChecklistCommon mistakes
- Using the same password for a password manager as for any other account.
- Not setting up 2FA on the password manager itself.
- Storing 2FA backup codes in the same password manager without a second copy elsewhere.
- Choosing SMS 2FA because it is easier — it significantly reduces your security.
- Not running a periodic audit of your vault to remove unused accounts with old passwords.
Related guides
Primary sources
Frequently asked questions
Why is SMS two-factor authentication not good enough for journalists?
Which password manager should I use?
What is a hardware security key and do I need one?
What should I do if my password manager vault is compromised?
Related guides
Primary sources
- Password Guidance: Simplifying Your Approach— National Cyber Security Centre
- Creating Strong Passwords— Electronic Frontier Foundation
- Bitwarden — Open-Source Password Manager— Bitwarden
- 1Password for Journalists (Safety Fund)— 1Password
- KeePassXC — Offline Password Manager— KeePassXC Project
- YubiKey Hardware Security Keys— Yubico
- Security Training for Journalists— Freedom of the Press Foundation