goJumboGPT

Security Passwords: how to make them strong and keep track of them

Sharing a password without putting it in a message

Why passwords in chat and email keep leaking, the safe ways to share access at home and at work, and what to use when the other person will not install anything.

8 min read How we write

The short answer

  • The best way to share a password is to use a feature that avoids sharing one: a family plan, an extra member slot, delegated access or a second card on the same account.
  • A password sent in chat or email is a permanent searchable copy that syncs, backs up and gets forwarded, and deleting your side does not remove it.
  • A password manager shared folder encrypts the item to each recipient and updates in place, so nobody has to ask what the new wifi password is.
  • Expiring one time links are the right answer for a single handoff to someone with no app, as long as the expiry is hours rather than days.
  • Revoking access does not erase what somebody already memorized, so a departure means rotating passwords as well as removing the person.
  • Never hand over online banking credentials, because it usually breaks your account terms and can change who carries the loss on a fraudulent transaction.

The safest way to share a password is not to share one. Most of the accounts people pass around by text message support a proper alternative: a family plan with separate profiles, an extra member slot, a delegated mailbox, a second card on the same bank account, or a work role that grants access without handing over credentials. When no such option exists, the next best thing is a password manager shared folder, then an expiring one time link, and only then anything typed into a conversation. The reason to care is simple: a message is a permanent, searchable, syncing, forwardable copy of the secret, and you lose control of it the moment you press send.

Why a password in a message keeps leaking

A chat message is not a handover, it is a copy that keeps existing. It syncs to every device on both accounts, including the tablet in the kitchen and the old phone in a drawer. It lands in a cloud backup that may not be encrypted the way the chat is. It is fully searchable years later, so anyone who ever gets into either account can type the word password and read the results.

Email is worse, because it sits on a mail server, gets indexed, and is exported wholesale during a job change, a legal request or an account compromise.

The smaller failures are the ones that actually happen. A preview appears on a lock screen. Someone forwards the thread to sort out a billing question, with the password still in it. Somebody screenshots it, and the screenshot syncs to a shared photo library. Delete for everyone does not help much, because by then the message has been backed up, notified and possibly photographed.

There is also a control problem no tool fixes: once the other person has the text, that account depends on their device and their habits, and you can see neither.

The first question: can you avoid sharing at all

Before choosing how to send a password, check whether the service has a feature that makes sending unnecessary. Far more do than people assume.

Streaming and music services generally offer household profiles or paid extra member slots, which give each person their own login and their own watch history. Cloud storage and photo services have shared folders and shared albums. Mail and calendar platforms support delegated access, where a colleague or family member can read or send on your behalf using their own account.

Banking deserves its own paragraph. Adding an authorized user, opening a joint account, or setting up formal third party access for an elderly relative all keep the credentials separate. Handing over your online banking login usually breaches the terms you agreed to, and those terms typically say that disclosing your credentials can affect who carries the loss on an unauthorized transaction. The specifics differ by country and by bank, so read your own agreement, and treat this as general information rather than advice about your situation.

At work the rule is one account per person plus permissions, never a shared login. If a system truly has no multi user support, the shared credential belongs in a team vault with an owner and a review date. Setting the household equivalent up once is the substance of a family tech setup that prevents most problems.

The hierarchy, from best to worst

MethodHow the secret travelsCan you revoke itBest forMain weakness
Delegated access or family planIt does not, each person has their own loginYes, immediately and completelyAnything that supports itNot offered by every service
Password manager shared folderEncrypted to each recipient, never in plain textAccess yes, memory noHouseholds and teams, ongoing sharingBoth people need the same app
Expiring one time linkEncrypted, self destructs after one viewExpiry does it for youA single handoff to someone with no appLink preview bots can consume the view
Split across two channelsPlain text, in two places instead of oneNoLast resort, low value accountsBoth channels are often the same phone
Chat or emailPlain text, stored and searchable foreverNoNothingPersists, syncs, forwards, gets screenshotted

Work down the list and stop at the first row your situation allows. Most household sharing belongs on row one or two, and most late night panic sharing lands on row five purely for speed.

How password manager sharing actually works

When you share an item from a manager, the app encrypts that item to the recipient's key rather than sending them readable text. The provider stores a scrambled copy it cannot read, and the recipient's app decrypts it locally. Nothing readable crosses the network and nothing readable sits in a message history. The underlying encryption model is described in how a password manager locks your vault.

The day to day benefits are less glamorous. A shared item updates in place, so when one person changes the wifi password everyone sees the new one instead of three people asking in a group chat. And because every household password is unique and generated, a leak at one shared service does not spread, which is the real cost of the alternative set out in why reusing one password is so expensive.

Some products offer a hide the password option, where the recipient can autofill but not view. Treat it as a convenience, not a control: a determined recipient can usually extract the value from the browser.

An expiring link service encrypts your text, stores the scrambled blob, and gives you a URL that works once or for a set period. The better implementations put the decryption key in the part of the URL after the hash symbol, which browsers do not send to the server, so the service holds an encrypted blob it cannot open. After the first view, or after the timer, the blob is deleted.

Burn on read has a second benefit. If your recipient says the link was already used, you have just learned that somebody else opened it, and you can rotate immediately instead of never finding out. Two cautions: set the expiry in hours rather than days, and be aware that chat apps which generate link previews can trigger the single view before your recipient taps it.

Splitting across two channels, sending half by message and half by voice call, is the weakest option that is still better than nothing. It only helps if the two channels are genuinely separate, and a text plus a WhatsApp message on the same phone are not. Reserve it for accounts where a leak would be mild, and never for email, banking or anything holding a card, which need long unique passwords that only you hold.

The two factor problem when two people share one login

This is where shared accounts quietly become insecure. One person sets up a second factor on their phone, the other person cannot sign in on a new device without ringing them, and after the third interruption somebody turns the second factor off.

There are three workable answers. Use a service with real multi user support, so each person has their own login and their own second factor. Or store the one time code seed in the shared vault entry, so both devices generate the same codes independently, which most managers support and which is explained in setting up an authenticator app properly. Or nominate one holder and put the printed recovery codes in the shared folder so the other person is not stranded.

Passkeys are the awkward case. They sync within one ecosystem and some platforms allow sharing with family, but crossing between Apple, Google and Windows households is still uneven, so a shared account often needs a password kept alongside the passkey.

What to do when the sharing ends

Departures are where shared credentials do their damage, because people remove the person and stop there.

  1. Rotate every password that person could see, not just the ones you meant them to use. If they had the household folder, that is the whole folder.
  2. Sign out all sessions on each account. A password change does not always end a session that is already open, and a logged in tablet can keep working for weeks.
  3. Check the recovery settings on your own accounts. Their phone number or email may still be listed as a recovery contact or a trusted device, which is exactly the hole covered in setting account recovery up properly.
  4. Look for forwarding rules and filters on shared mailboxes, connected third party apps, and any device still listed as trusted.
  5. At work, disable the account first and rotate afterward, collect any hardware keys, and transfer ownership of documents before deletion rather than after.
  6. Close the accounts nobody needs any more, properly rather than by logging out, using the steps in deleting an online account for real.

Then do the setup you meant to do originally. Put the household passwords in one shared folder, move each service that supports it onto separate profiles or member slots, and agree out loud that nothing gets sent in a message again. The setup that survives is the one where the easy path and the safe path are the same, which is why a shared folder beats good intentions about deleting texts.

Common questions

Is it safe to send a password over an encrypted messaging app?

Safer than plain SMS or email, but still not good. End to end encryption protects the message in transit, not after it arrives. It stays in both chat histories, syncs to every linked device, appears in backups and can be screenshotted or forwarded. Disappearing messages help a little. If you must use chat, turn on a short disappearing timer and change the password once the other person no longer needs it.

How do I share a streaming account with family without giving out my password?

Use the household or extra member feature the service sells rather than handing over credentials. Each person gets their own profile, their own recommendations and their own login, and you can remove them without changing anything. If the service has no such option and you do share, use a password manager folder, give it a unique generated password, and keep the payment card off that account where possible.

What should I do if I already texted someone a password?

Change it, then decide how to share it properly. Deleting the message is worth doing but does not undo the copies already made on the other device or in backups. Change the password on the account, share the new one through a manager folder or an expiring link, and if the account holds money or personal documents, also sign out all sessions and check the recovery settings.

Can I share a password with someone who will not install anything?

Yes, with an expiring one time link. You paste the secret into the service, it encrypts it, and you send a URL that works once or for a few hours. The recipient just opens a web page. Set the shortest workable expiry, tell them to open it straight away, and remember that a chat app generating a link preview can sometimes consume the single view before they get there.

Is it safe to share passwords through a shared note or spreadsheet?

No. A shared document keeps the passwords in readable text, usually in a place with broad access, version history that survives deletion, and no record of who read what. Anyone who gains access to that one document gets everything at once. If you have such a file, move the contents into a shared vault, then delete the file and its version history.