For years I treated password advice like a moving target. First it was long random strings. Then it was a password manager. Then it was two-factor codes. Now the conversation has shifted to passkeys. Each new recommendation arrived with the implication that whatever I was doing yesterday was already outdated.
The result, for most people I talk to, is decision fatigue. They keep the same reused passwords because the “right” system feels like a project they never finish.
This article is the opposite of a project. It is the smallest setup that actually works for an ordinary adult who has email, banking, shopping, and a couple of social accounts—and who does not want a second job managing credentials.

What Problem We Are Actually Solving
Most account takeovers still begin with one of three failures:
A password reused across sites
A password guessed or stolen because it was weak
A recovery path that no longer works
Passkeys and password managers both address the first two. Neither replaces the need for a working recovery method. The goal is not to adopt every new standard. It is to stop the failures that actually happen.
Passkeys in plain language
A passkey is a cryptographic credential stored on your device (or in a cloud keychain) that lets you sign in without typing a password. When a site supports it, you approve the login with a fingerprint, face scan, or device PIN. There is nothing to remember and nothing reusable for an attacker who steals a password database.
Passkeys are excellent where they are available. They are not yet universal.
Minimum Effort: The Setup That Covers Most Real Risk
You do not need to convert every account this weekend. You need two things working:
A password manager for the accounts that still use passwords
Choose one reputable manager, install it on your phone and primary computer, and save unique passwords for your email, primary financial accounts, and main shopping logins. Let the manager generate the passwords. You only need to remember the master password (or use the manager’s biometric unlock).Passkeys on the sites that already offer them
Start with your primary email, the major tech accounts you use daily, and any financial site that shows a passkey option. Enabling a passkey usually takes less than a minute per site and removes the password from the login flow entirely.
That combination—unique passwords where required, passkeys where available—stops the majority of credential-based takeovers without requiring a complete migration.
What you can safely postpone
You do not need to:
Move every old forum or newsletter login into the manager on day one
Replace hardware security keys yet
Force passkeys on sites that still make the process awkward
The high-value accounts first. The long tail later.
If You Want to Go Further
Once the minimum setup is running, three additional steps raise the floor without turning the system into a chore:
Turn on the password manager’s built-in two-factor or biometric protection for the vault itself.
Add a hardware security key (or a second device) as a backup sign-in method on your primary email and financial accounts.
Review the “passkeys and security keys” section on your major accounts once or twice a year and remove any devices you no longer own.
These steps matter most if you travel frequently, share devices, or simply want a cleaner recovery path when a phone is lost.
A practical note on choosing a manager
I have used both free and paid options. The free tier of a reputable manager is enough for most people. Paid plans mainly add family sharing, priority support, and a few convenience features. Choose the one whose apps feel least annoying on the devices you already own. The best manager is the one you will actually open.

What I Use Day to Day
My current setup is deliberately boring:
One password manager holding unique credentials for every account that still needs a password
Passkeys enabled on the half-dozen sites that support them cleanly
Backup codes stored in the manager and on a printed sheet in a known place
No attempt to make every last login perfect
It has survived lost phones, new laptops, and the usual stream of breach notifications without drama. That is the test that matters.
The Next Thing
Open your primary email account today and look for a passkey or “passwordless” option. If it exists, turn it on. If it does not, open a reputable password manager, create a strong unique password for that email account, and save it.
Either action removes the single most common way that account gets taken over.
You don’t have to do everything. Just do the next thing.
No notes yet — be the first to inscribe one.