← Back to all tech guides
🔐 Security Guide

Senior-Friendly Password Management — A Plain-English Guide

Last verified: August 2026

Layers of Password SafetyFrom simplest to strongest. The best one is the one you'll actually use.Password bookPaper, at homeOkay if hiddenNever carry itPhone's manageriCloud Keychain orGoogle, built inFree & automaticPassword app1Password / BitwardenOne master passwordShares with familySealed envelopeBackup for a crisisMaster + codesTrusted person onlyThe manager already on your phone is free, safe, and remembers passwords for you.Illustration - a simplified picture; your details may differ.
Four honest layers, from a simple written book to an app - pick what you'll actually use.
Where Your Login Code Comes FromTwo-factor sends a second code. Some ways are stronger than others.Text messageCode by SMSEasy, familiarCan be interceptedAuthenticator appCode on your phoneRefreshes every30 seconds - strongerSecurity keyA small USB/tap keyHardest to foolFor high-value loginsAn authenticator app is a big step up from texted codes - and still simple to use.Illustration - a simplified picture; your details may differ.
The three places a second-step code can come from, weakest to strongest.

One good password between you and the rest of your accounts. The printed password book (yes, really). The free password manager already on your phone. The sealed envelope for the just-in-case day. Calm, plain English, no fear, and a real person to call if you get stuck.

For
Seniors & their families
Covers
Books, apps, 2FA, recovery
Best Use
Drawer with the book
Bill's Hotline
(330) 200-8042

Why One Good Password Matters

Most folks I sit down with have somewhere between thirty and a hundred accounts they don't think about — email, bank, Amazon, Facebook, the doctor's portal, the cable company, that knitting site you joined in 2014. The uncomfortable truth is that almost all of those accounts are protected by the same handful of passwords, usually some version of Buckeye2010! with a number on the end. When one of those websites gets hacked — and they do, every week — the bad guys try that password on every other account you own.

Here's the calm version of the rule: you only need to remember one really good password. The email password. Because if somebody gets into your email, they can reset every other password you own. The email is the front door. Everything else is just rooms in the house.

The rest of this guide is about how to make that one good password, where to put it so you don't lose it, and how to set things up so your phone or your computer remembers the other ninety-nine for you — without you having to become a tech person. If you'd rather skip the reading, call me at (330) 200-8042 and we'll do it together at your kitchen table.

👨‍👩‍👧 For the Adult Kids — A One-Page Plan

If you're reading this for a parent, here are the four things that matter most. Any one of them, done in an afternoon, would prevent most of the lockouts I get called about.

  1. Buy them a password book. Drugstore or bookstore, $10-$15. Write the email, bank, Apple ID or Google account, and phone passcode in it together. The other accounts get added over time.
  2. Turn on iCloud Keychain (iPhone) or Google Password Manager (Android). Already on their phone. Free. Most folks have never opened it. Spend 30 minutes setting it up.
  3. Seal the "in-case-something-happens" envelope. Apple/Google master password, phone passcode, where the password book lives, who to call. Sign across the seal. One trusted person knows where it is.
  4. Schedule Bill's passwords visit. $99, about 90 minutes, in their home. We do all of the above, plus turn on two-factor and print recovery codes. 30-day follow-up included. Call (330) 200-8042.

Bring it up gently. Don't lead with "I'm worried about you." Lead with "I just read this guide and I want to do it for myself too — would you do it with me?" Going first works.

Bill's Honest Take: The Password Book is Okay

For about twenty years, every well-meaning tech magazine told people: never write your passwords down. That advice was wrong, and it caused more damage than the alternative. What actually happened is that millions of people — unable to remember a hundred different passwords — just used the same one everywhere. That's worse. Much worse. A scammer in Lagos guessing your reused password is a real threat. A burglar breaking into your house specifically to find a notebook labeled passwords is not.

Walk into any drugstore with a stationery aisle and you'll find a little book labeled Internet Password Logbook for under fifteen dollars. They are perfectly fine. I recommend them. The only thing that matters is that you actually fill it in and you keep it somewhere reasonable — not face-up on the kitchen counter when the cleaning service comes.

Bill's note

The "never write it down" advice caused more lockouts, more reused passwords, and more weekend emergency calls than just about any other piece of bad tech wisdom. Buy the book. Fill it in. Lock the drawer. You're done.

What to Write in the Book — and What NOT To

✅ Do write

  • The website or app name. "Chase Bank," "Gmail," "Amazon." Plain English.
  • Your username or login email. So you don't have to guess which email you used.
  • The password itself, written clearly. A 7 looks like a 1 when you're tired.
  • The date you set it. Month and year. Tells you which one is current when you've crossed one out.
  • An account hint. Like "the one with the rewards points" or "the joint account."

🚫 Do NOT write

  • Your 4-digit ATM PIN. Never in the book, never in the phone, never on the back of the card. Your PIN lives in your head. Period.
  • The 3-digit CVV from a credit card. No legitimate reason to write that down.
  • Your full Social Security number. Goes in the sealed envelope, not the book.
  • Honest answers to security questions. Treat those answers like passwords too — make them up. "First pet" can be blueberry-truck-1962. Now even somebody who reads your obituary can't get in.
Bill's note

I bring an empty password book to most senior visits and we fill in the first ten or fifteen accounts together. Email, bank, Amazon, Medicare, the doctor's portal. After those, you can do the rest at your own pace. Never leave the book open on the counter — that's the one habit that's most of the security.

The Tools Already On Your Phone

Whichever phone you have, a free password manager is already installed. Most folks I meet have no idea it's there. Here's how to find yours.

🍎 iCloud Keychain — for iPhone & iPad

Apple built a password manager right into every iPhone and iPad. When you log into a website on Safari and your phone asks "Would you like to save this password?" — that's iCloud Keychain. Say yes.

What it does for you:

  • Remembers every password you've ever told it to remember.
  • Fills passwords in for you when you go back to a website — usually with Face ID or a fingerprint.
  • Suggests a strong unique password when you sign up for something new.
  • Syncs the same passwords to your iPad and Mac signed into the same Apple ID.
  • Warns you if a saved password shows up in a public data breach.

Where to find it: Settings → Passwords (or Apps → Passwords on newer iPhones) → unlock with Face ID or passcode. There's everything your phone has been quietly saving for you.

The catch: Everything in iCloud Keychain is locked behind your Apple ID password and your iPhone passcode. Those two are now the most important passwords in your life. Write them in the book. Put the Apple ID password in the sealed envelope too.

🤖 Google Password Manager — for Android & Chrome

Google built the same kind of thing into Android phones and the Chrome browser. Free, already there, and most folks have never opened it.

What it does for you:

  • Saves passwords the first time you log into a site in Chrome.
  • Fills them in next time, on every device signed into the same Google account.
  • Generates strong new passwords when you're signing up somewhere new.
  • Runs a "Password Checkup" that flags anything weak, reused, or leaked.

Where to find it: on Android, Settings → Google → Manage your Google Account → Security → Password Manager. On any computer with Chrome, type passwords.google.com in the address bar.

Same catch as Apple: everything is locked behind your Google password. That makes that password the master key. Book, envelope, two-factor turned on — same drill.

When You Want More — 1Password and Bitwarden

If the built-in tools cover what you need, skip this section. If you want to share logins with a spouse or an adult child, or you use a mix of devices that don't all play nicely with each other, a dedicated password manager is worth considering.

👨‍👩‍👧 1Password Families — great for sharing

1Password is a paid password manager. The Families plan does one thing the free built-in tools don't do well: it lets you share a folder of important logins with a spouse, an adult child, or both. Safely. With history. Without emailing passwords around.

Worth it when:

  • You and your spouse share most accounts (bank, insurance, streaming, utilities).
  • You want an adult child to be able to help you with logins from their phone.
  • You'd like one trusted person to step in for important accounts if something happens.
  • You use a mix of devices — iPhone + Windows, etc. — and want one tool that works everywhere.

How it works: each family member has a private vault — their own locker. A shared vault in the middle holds joint accounts. When you change a password, everyone's phones update automatically.

Current pricing: a monthly subscription for up to five people. Pricing changes — check 1password.com for the current rate.

🆓 Bitwarden — the free, open-source option

Bitwarden is a password manager a lot like 1Password, with one main difference: it has a free tier that's actually generous enough for one person to use every day. No tricks. No 30-day trial that turns into a charge.

Why people like it:

  • Free for one person — unlimited passwords on unlimited devices.
  • Open source — security folks have been kicking the tires for years and saying it holds up.
  • Works everywhere — iPhone, Android, Mac, Windows, Chrome, Safari, Firefox.
  • Paid family plan exists too if you want sharing — usually cheaper than 1Password Families. Check bitwarden.com for current pricing.

Where it's less polished: 1Password feels a little more finished — fewer rough edges, prettier app. Bitwarden is perfectly good, just a little more utilitarian.

Bill's note — how I pick for folks

Single senior, comfortable with the phone, tight budget — Bitwarden free is great. Married couple wanting to share, or anyone who'd rather pay a few bucks for the smoothest experience — 1Password Families. Already happy with iCloud Keychain or Google Password Manager — keep what you've got, no need to switch. There is no wrong answer here. The wrong move is paralysis.

Choosing One Master Password You Can Remember

Whichever manager you use, there's one password you have to remember on your own — the one that locks the manager itself. The old advice ("use a capital letter, a number, and a symbol") gives you things like P@ssw0rd1!, which is easy for computers to guess and hard for humans to remember. Worst of both worlds.

The better way: three random words. Pick three ordinary words that don't go together. String them with dashes. Add a number on the end if a site demands one. Examples (pick your own, don't use these):

truck-pancake-hollyhock · balloon-october-stairwell · kettle-marigold-railway42

Each of those would take a modern computer billions of years to guess by brute force. And you can remember any of them after three or four uses. Open a dictionary, a cookbook, and a gardening book to random pages. Pick the first noun you see on each. That's your starting point.

What NOT to use:
  • Your name, your spouse's name, your kids' or pets' names.
  • Your birthday, anniversary, address, or phone number.
  • The word password in any form.
  • "Buckeye," "Browns," "Cleveland," "Atwater" — anything a scammer could guess from your Facebook or your location.

The "In-Case-Something-Happens" Sealed Envelope

Here's the situation nobody likes to talk about: something happens — a stroke, an accident, even a few days in the hospital — and your spouse or your adult kid suddenly needs to get into your accounts. Pay a bill. Cancel a subscription. Reach the people in your contacts. And they can't, because everything is locked behind passwords only you know.

There's a simple fix. I call it the sealed envelope. It's exactly what it sounds like.

✉️ What goes inside

  • Your iPhone or Android passcode (the 6 digits that unlock the phone).
  • Your Apple ID or Google account password — the one that locks the cloud.
  • Your email password, if it's different.
  • Your bank's online-banking login — username and password.
  • The master password for your password manager (if you use one).
  • The router admin password.
  • A short note: "The full password book is in <exact drawer>."
  • One name and one phone number — the person to call first.

How to seal it: print or hand-write it. Date it. Seal a paper envelope. Sign across the seal. Write on the front: OPEN ONLY IF I CAN'T. Call <trusted name> first. Store it somewhere fireproof or somewhere one trusted person knows about. Not a safe deposit box — banks have hours, emergencies don't.

Bill's note

I've watched two families try to wind down a parent's digital life without this envelope. Both times it took weeks, lawyers, and at least one fight. With the envelope, it takes an evening. This is the kindest gift you can leave for whoever has to step in someday.

Trusted Contacts — Apple, Google & Facebook

The big three companies each have a built-in feature where you can designate a trusted person now who can step in later. Free. Five minutes per account. Almost nobody knows it exists.

  • Apple — Account Recovery Contact & Legacy Contact: Settings → tap your name → Sign-In & Security. Account Recovery helps you get back in if you forget your password. Legacy Contact can request your data after you're gone, with a death certificate.
  • Google — Inactive Account Manager: myaccount.google.com → Data & privacy → scroll to Inactive Account Manager. Google asks: if my account isn't touched in 3-18 months, what should you do? Up to ten trusted people can be notified.
  • Facebook — Legacy Contact: Settings & privacy → Settings → Memorialization Settings. One friend can manage your memorialized page after you pass away.

Two-Factor Authentication Without Panic

Two-factor authentication ("2FA") means a site asks for two things instead of one: your password, plus a 6-digit code from somewhere only you have. Even if a scammer knows your password, they can't get the code. It is by far the most powerful free security upgrade you can make. Turn it on for email, bank, and Apple/Google. Today, if you can.

📱 Where the code comes from — and which to pick

  • Text message (SMS): easiest. Familiar. Dramatically better than no 2FA.
  • Authenticator app (Authy, Google Authenticator, Apple's built-in): better still — it lives on your device, isn't tied to your phone number, and works without cell signal. Slightly more steps to set up.
  • Physical security key: overkill for most folks. Skip it.

Bill's honest middle ground: if the choice is between no 2FA and SMS 2FA, pick SMS every time. If you'll install one extra app, an authenticator app is better. Don't let "which app" be what stops you. SMS is great. Start there.

When 2FA Goes Wrong

Five things that can happen — with the actual fix:
  • "I never got the text." Wait two minutes. Check cell signal. Tap "Resend code." If still nothing, look for "Try another way."
  • "My phone died." Plug it in. While you wait, grab your recovery codes (next section).
  • "I lost my phone." Your accounts are still safe — the phone needs your passcode too. Log in elsewhere with recovery codes, remove the lost phone from "trusted devices," and call your carrier to suspend the SIM.
  • "No signal." SMS codes can't reach you. This is exactly why an authenticator app beats SMS.
  • "I changed my phone number." Before you switch, update the number on every account that texts you codes — email, bank, Apple/Google, Amazon, Facebook, doctor's portal.

Recovery Codes — Print Them, Hide Them

When you turn on two-factor for an important account, the site usually offers recovery codes — eight or ten one-time codes you can use in place of a phone code. They're your way back in if you lose your phone or 2FA glitches.

What to do with them:
  1. Print them. One sheet per account. Label the sheet.
  2. Put them in the sealed envelope (or a separate envelope just for codes).
  3. Cross each one off as you use it. After a few are used up, log into the site and generate a fresh batch.
  4. Don't put them in the same place as the password. If somebody finds both, 2FA is useless.
  5. Don't take a screenshot. Pictures of these end up in cloud photo libraries. Print only.

Account Recovery for the Big Four

🍎 Apple ID recovery

Start at iforgot.apple.com. Apple offers three paths depending on what you've set up: a trusted device you're already signed into, an Account Recovery Contact who reads you a code, or a slow "Account Recovery" that takes a few days. Apple's main support line, 1-800-MY-APPLE (1-800-692-7753), is free and full of real humans who are good at this.

🌐 Google account recovery

Start at accounts.google.com/signin/recovery. Google's recovery flow tries every backup it knows — recovery phone, recovery email, old passwords. Answer honestly; "don't know" is better than guessing. Recovery can be instant or take 24-72 hours.

Important: Google does NOT have a real-human support phone line for free accounts. Anyone on the phone claiming to be Google support is a scammer.

📘 Facebook recovery

Start at facebook.com/login/identify. If you set up Trusted Contacts in advance, 3-5 friends can each receive a security code; you combine them and you're back in. If you think you were hacked, go to facebook.com/hacked and be patient. Don't pay anyone offering "fast recovery."

🏦 Bank account recovery

This is the one place you should NOT trust the internet to handle alone. Find the phone number on the back of your debit card — that's the real one. (Don't Google customer service numbers — search results are full of scam numbers.) Call. Tell them you're locked out. They'll verify you and walk you through a reset.

Watch out for: fake bank texts asking you to "verify," and fake bank phone calls. Caller ID can be faked. When in doubt, hang up and call the number on the back of the card.

The Grandparent Fallback Plan

Some folks read everything above and say "Bill, I'm not going to do any of that." Fair. So here's the absolute minimum that puts you well ahead of most people:

  1. Buy a password book at the drugstore. Write your email, your bank, your Apple ID or Google account, and your phone passcode in it. Just those four to start.
  2. Tell ONE trusted adult kid or friend where the book lives. Don't show them what's in it. Just where it is.
  3. Make sure that one trusted person has your Apple ID password OR your Google account password. That's the master key — with it, they can step in and reach almost everything in an emergency.

You don't have to call a family meeting. The conversation is ninety seconds long and sounds like: "Hey honey. If anything ever happens to me, the password book is in the second drawer of the desk. Master password to my Apple ID is on page one. You don't need to do anything right now — I just wanted you to know where it is."

The Annual Audit — One Afternoon, One Coffee

Once a year — your birthday week is a good one — brew a pot of coffee, call an adult kid or trusted friend on speakerphone, open the password book to page one, and work through this:

  1. Email password — still working? Change it if it's been more than a year.
  2. Bank password — change yearly. Confirm 2FA is on.
  3. Apple ID or Google account — the master key. Treat it well.
  4. Phone passcode — verify it works. Change if 3+ years old.
  5. The sealed envelope — open, compare, rewrite if anything's changed, seal a new one, shred the old sheet.
  6. Trusted contacts — still the right people? Update.
  7. Recovery codes — generate fresh, print, shred the old.
  8. Trusted devices — sign out anything you don't recognize.
  9. Dead accounts — anything you haven't used in two years? Cancel it.
  10. Recovery phone & recovery email — current on every important account?
  11. Any passwords still listed as Buckeye2010? This is the year. Let the password manager generate strong new ones.
Bill's note — why with a kid on speakerphone?

Two reasons. First, a second pair of eyes catches mistakes you'd miss. Second — and more important — your adult kid gets familiar with the system. If anything happens later, they're not learning your setup at the worst possible moment. Once a year. One afternoon.

The Fake Password Reset — A Scam in Disguise

Half the security calls I get start with one of these. The bad guys know that an email saying "your password was reset" or "unusual sign-in attempt" scares people enough to act fast. Fast is the scammer's friend.

What you'd actually see: "Apple ID Security Alert. Your password was just changed from a device in Lagos, Nigeria. If this wasn't you, click here immediately to reverse the change and secure your account."
Why it works: The email looks real — logo, language, panic all on point. You tap the link. It opens what looks exactly like Apple's sign-in page. You type your password to "reverse the change." Except the page isn't Apple. The page is the scammer. You just handed them your password by responding to the fake alarm they set off.
How to spot it every time:
  • You didn't start it. Real password changes start with you clicking "forgot password."
  • The link doesn't go to the real site. Long-press on a phone (or hover on a computer) to see where it really goes.
  • The email pushes you to hurry. Real security alerts don't have a 10-minute fuse.
  • Anyone on the phone is the giveaway. Real companies never call to "help" you with a reset.
The clean fix: Don't click the link. Open a new tab. Type apple.com (or whatever) yourself. Log in normally. If something is actually wrong, you'll see it on the real site. Almost always, nothing's wrong — the email was bogus.

The one-rule version: If you didn't start the reset, don't finish it. That sentence is the whole defense against this scam.

Bill's Rules of Thumb — One Last Page

If you ever can't remember what to do, these cover almost everything in this guide. Worth posting on the fridge:

  1. One good password — your email — written down, with two-factor on. That's most of the game.
  2. The book in the drawer is a tool, not a sin. Use it.
  3. iCloud Keychain or Google Password Manager is already on your phone, free. Remembers the rest for you.
  4. The sealed envelope is the kindest thing you can do for whoever steps in someday.
  5. Two-factor on for email, bank, and Apple/Google. Recovery codes printed.
  6. One trusted person knows where the book lives. Just one.
  7. Once a year, with coffee and a kid on speakerphone.
  8. "You started it" defeats every password-reset scam.
✂️ Cut this out — stick it on the fridge

📞 Bill's Lockout Hotline

(330) 200-8042

Call me first — always free — if:

  • You're locked out of email, bank, or your Apple ID / Google account.
  • You got a "your password was changed" email and you didn't change it.
  • Someone is on the phone trying to "help" you reset a password.
  • Your phone is lost, broken, or you're switching phone numbers.
  • You'd like help printing recovery codes or sealing the envelope.

My promise: If you call me about a possible lockout or scam, I will call you back within 24 hours, no charge, no judgment. Mon–Sat, 9:00 AM – 7:30 PM normally.

Wallet Card — Laminate & Carry

Cut this out, fold it once, slip it behind your driver's license. 30-second sanity check for any "security alert" that makes your stomach feel funny.

🔐 Bill's 30-Second Password Check

  • Did I start this reset? If no, it's probably fake.
  • Is the link the real site? Long-press to see the real address.
  • Is it pushing me to hurry? Hurry = trap.
  • Is anyone on the phone "helping"? Hang up.
  • If unsure → close it. Type the address yourself. Or call Bill: (330) 200-8042

Bill's Home Tech · Atwater, Ohio · bill@billshometech.com

Quick Glossary — Words You'll Hear

Password manager
An app on your phone or computer that remembers all your passwords for you behind one master password. iCloud Keychain, Google Password Manager, 1Password, and Bitwarden are all password managers.
Master password
The one password you have to remember on your own — the one that unlocks the password manager. Three random words is the easiest way to make a strong one.
Two-factor authentication (2FA)
An extra layer of security where a site asks for two things to let you in — your password, plus a 6-digit code from your phone or an app. Best free defense there is.
Recovery codes
One-time codes a site gives you when you turn on 2FA. Print them. Hide them in the sealed envelope. They get you back in if you lose your phone.
iCloud Keychain
Apple's built-in password manager. Free. Already on every iPhone, iPad, and Mac. Most folks have never opened it.
Google Password Manager
Google's built-in password manager. Free. Already in the Chrome browser and on every Android phone.
Trusted contact
A person you designate in advance who can help you recover your account if you're locked out (Apple, Google, Facebook all let you do this).
SIM swap
A scam where the bad guys trick your phone company into moving your number to their phone — so SMS codes go to them instead of you. This is why authenticator apps beat SMS for 2FA.
Sealed envelope
The analog version of digital estate planning. A paper envelope with your most important passwords, sealed, signed across the seal, stored where one trusted person can find it.
Three random words
A method for making a strong, memorable master password — three ordinary unrelated words strung together. Easier for you to remember, harder for a computer to guess.

Want Me to Walk Through This With You?

I do a "passwords visit" — $99 flat, in your home. About 90 minutes at the kitchen table. We set up your password book, turn on iCloud Keychain or Google Password Manager, pick a master password you'll actually remember, turn on two-factor for the four most important accounts, print recovery codes, and seal your in-case-something-happens envelope. 30-day follow-up included. It's the visit I wish more people scheduled before they get locked out, not after.

🏡
In Your Home
No remote runaround. I come to you.
💵
$99 Flat
First visit, no surprise charges.
📅
30-Day Follow-Up
Included with every visit.
📍
Local
Based in Atwater — serving Portage County.

Would you rather I just do this for you?

No shame in it — plenty of folks would rather hand it off, and that's what I'm here for. I'll come to your home, set it up right, and make sure it's working before I leave. Flat $99 per visit — no jargon, no upsell, and every visit is 30-day come-back-free.

Not a hardware job? I can often fix it remotely for $49 — a secure screen-share, up to 2 hours, that you watch the whole time and can end whenever (included free for $39/mo Support Plan members, and it counts toward the $99 if it turns out I need to come out).