Skip to main content

Password Managers & Two-Factor Authentication

Account takeovers are one of the most common ways journalists are targeted. A password manager and strong 2FA are the two highest-impact security measures most people can adopt in under an hour.

General guidance, not professional security advice. For high-risk threat models involving state actors or organised crime targeting, consult a qualified security professional or the Access Now Digital Security Helpline.

Last reviewed: Next review due:

Why passwords matter for journalists

Journalists are high-value targets for account takeovers. A compromised email account exposes source communications, unpublished stories, and contact details. A compromised social media account can be used to spread disinformation, approach sources under false pretences, or destroy a journalistic reputation. Weak or reused passwords are the most common cause of account compromise — and they are entirely preventable.

A password manager generates a unique, random, strong password for every account. You only need to remember one master password. Combined with strong two-factor authentication (2FA), this makes account takeover extremely difficult for all but the most sophisticated attackers.

Password manager comparison

1PasswordBest usability

Commercial, cross-platform, excellent browser integration. Travel Mode lets you hide vaults when crossing borders. Journalist Safety Fund offers discounts. ~£3/month.

BitwardenBest free option

Open-source, free tier covers most needs, premium ~£10/year. Cloud-hosted by default; can self-host for maximum control. Independent audits conducted.

KeePass / KeePassXCOffline / maximum control

Free, open-source, vault stored locally — never on a cloud server. Requires manual sync between devices (e.g., via an encrypted USB or Syncthing). More technical setup but no cloud dependency.

2FA options ranked by strength

  1. 1 — Best: Hardware security key (YubiKey, Google Titan)

    Phishing-resistant. Physical device required to authenticate. Cannot be intercepted remotely.

  2. 2 — Good: TOTP app (Authy, Google Authenticator, Aegis)

    Time-based codes generated on your device. Phishable by sophisticated fake login pages but far better than SMS.

  3. 3 — Avoid if possible: SMS / phone call 2FA

    Vulnerable to SIM-swap attacks. Only use if no better option is available. Never for your most critical accounts.

Red flags

  • You reuse the same password on multiple accounts.
  • Your passwords are stored in a spreadsheet or text file.
  • You use SMS as your primary 2FA method on high-value accounts (email, cloud storage, social media).
  • You have no 2FA enabled on any account.
  • Your password manager master password is the same as another account password.
  • You have not set up an offline backup of your vault in case you lose access.

Password & 2FA checklist

  • I use a password manager for all accounts.
  • Every account has a unique, manager-generated password.
  • My password manager master password is long, unique, and memorised (not written on a sticky note).
  • 2FA is enabled on all critical accounts: email, cloud storage, social media, bank.
  • I use TOTP or a hardware key for 2FA — not SMS — on my most sensitive accounts.
  • I have an offline backup of my password vault (exported and stored on an encrypted USB).
  • I know the recovery procedure if I lose access to my 2FA device.

Source protection checklist

Account security is part of source protection. Check whether your setup is adequate.

Source Protection Checklist

Common mistakes

  • Using the same password for a password manager as for any other account.
  • Not setting up 2FA on the password manager itself.
  • Storing 2FA backup codes in the same password manager without a second copy elsewhere.
  • Choosing SMS 2FA because it is easier — it significantly reduces your security.
  • Not running a periodic audit of your vault to remove unused accounts with old passwords.

Related guides

Primary sources

Frequently asked questions

Why is SMS two-factor authentication not good enough for journalists?
SMS 2FA is vulnerable to SIM-swap attacks, where an attacker convinces your mobile operator to transfer your phone number to a SIM they control. They then receive your 2FA codes. Journalists are sometimes targeted by SIM-swaps — particularly those covering stories that attract well-resourced adversaries. Use TOTP (time-based one-time password apps like Authy or Google Authenticator) or, best of all, a hardware security key like YubiKey instead.
Which password manager should I use?
1Password and Bitwarden are the most widely recommended for journalists. 1Password is commercial but has excellent usability and a Journalist Safety Fund discount programme. Bitwarden is open-source and free (with a premium tier). KeePass is an offline option — your vault never touches a cloud server — but requires more technical comfort and manual sync between devices. All three are far better than reusing passwords or using a browser's built-in password manager without a master password.
What is a hardware security key and do I need one?
A hardware security key (such as a YubiKey or Google Titan Key) is a physical device that plugs into a USB port or taps via NFC to authenticate you. It is the strongest form of two-factor authentication because it is phishing-resistant — it will not authenticate with a fake login page. For accounts that are particularly high-value (email, social media, cloud storage), a hardware key significantly raises the bar for an attacker. For most journalists covering sensitive beats, a hardware key for the accounts most critical to your work is a worthwhile investment.
What should I do if my password manager vault is compromised?
Change your master password immediately. Revoke all active sessions. Audit which accounts are stored in the vault and change the passwords for the most sensitive ones first — email, cloud storage, social media, financial accounts. Enable the most secure 2FA available on those accounts. Report the compromise to the password manager provider. If you use a hardware key as the 2FA for your vault (recommended), an attacker with your master password alone cannot log in.