Checks > First time setup > C-04
People compose passwords from a small personal vocabulary, and the substitutions they apply are the same substitutions everyone applies. The result is shorter and more guessable than its length suggests. A generated string has none of that structure, which is the entire point.
Uniqueness matters more than complexity here. A very strong password reused across accounts is still a single point of failure, because a breach anywhere it was used exposes it everywhere. A merely adequate password used in exactly one place cannot be leaked by somebody else mistake.
A password manager on your own machine, rather than a browser sync feature tied to an account with your name on it. The manager holds the string so you do not have to choose between memorable and strong, which is the trade that produces weak passwords in the first place.
Two factor. A password alone, however good, is one leak away from being enough. The item on recovery material and two factor covers that, and the two together are what make a credential leak survivable rather than fatal.
nexusb2l7fmqnefwphyy7m5zjhlkytlbo7qbb5lu5dlczr3azgii2gyd.onionnexusma2iqgauqqvjcgds4ckv5xbf272tkfagq4epojjhsgleqpwxiqd.onionnexusabcd6tyfhdwilyitaqiri6tisj2v2hueyjuj6qkvd6azvi5tuqd.onionRun C-07 before you type anything. Open in Tor Browser only, then compare the onion printed on the login screen against your browser address bar. A mismatch means the page is a copy and the tab should be closed.