Just realized I stopped reusing passwords in 2021, and my whole login routine looks totally different now
Back in 2019 I had maybe 4 passwords for 30+ accounts, and I kept them in a note on my phone. After a site I used for work got hit, I had to reset 12 logins in one afternoon, which was a nightmare. Now I use a password manager plus a security key for my email and bank, and every site gets its own long random password. The biggest change was adding 2FA everywhere I could, even on my pizza app, because that one breach taught me how fast things spread. The other shift is I stopped saving cards on random shopping sites and just type them in each time. What finally got you to ditch the old reused password, or are you still holding out?
That line about the pizza app hits home. Once you add 2FA to the dumb stuff, you start to see how one leaked password can snowball, because the bad guys don't care if it's your bank or your dinner order, they just try the same combo everywhere. The part people miss is that old passwords never really die, they sit in lists that get traded around for years. So even if you change one account today, a breach from 2018 can still bite you later. That's the real reason to go unique on every site, not just the important ones. What sold me was reading about credential stuffing, where they just spray thousands of username and password pairs at a login page until something works. Takes minutes and nobody has to guess anything.
The bit about old passwords never really dying is so true, it's like how that one weird smell in your fridge just keeps coming back no matter what. @lewis.brian nailed it with credential stuffing too, it's the same lazy math as spam calls where they dial a million numbers hoping one person picks up. Once you see it as a numbers game, being the one lazy account in the pile stops feeling worth it.