The Ordinary Review

Careful reporting on everyday money

Innovation

Forty New Accounts Since October? The Year-End Pass That Keeps a Password Vault Honest

Holiday shopping leaves a trail of accounts nobody planned to keep. Here is what the current standards ask of you, and the annual pass that settles it in one evening.

Lucinda Fairbairn|

A laptop on a kitchen table showing a password manager's list of saved accounts, beside a stack of holiday shipping receipts and a credit card
A laptop on a kitchen table showing a password manager's list of saved accounts, beside a stack of holiday shipping receipts and a credit card

Between the first cold week and the second week of January, most households open more online accounts than they will in the rest of the year combined. A checkout page asks for a password to save a shipping address, a gift card lands with its own portal, a streaming trial gets started for a visiting relative and never gets closed. None of it feels like a decision. By February the vault holds forty entries whose purpose nobody remembers, and the person who set them up is the one who will pay for the untidiness later, usually at an inconvenient hour.

What the standards ask for now, and what they stopped asking

The National Institute of Standards and Technology is responsible for the federal guidance on digital identity, and its current position on memorized secrets is materially different from the rules most of us were trained on. Length carries the weight, composition rules do not, and forced expiration on a calendar is no longer treated as a control that earns its cost. What replaced it is screening: a password is checked against known compromised lists at the moment it is chosen, and rotated when there is evidence it has leaked rather than because ninety days have passed. That single change reorganizes the whole annual chore.

It also changes what a good entry looks like. A long passphrase you would recognize on sight beats a short string of substituted characters, pasting from a manager should be permitted and increasingly is, and hints and forced security questions are treated as liabilities rather than backstops. If you have done this a few times, you already know the practical version of that guidance: the strength of the account rarely turns on the password itself anymore. It turns on whether a second factor is attached, and on which email address sits behind the reset link.

The accounts the season leaves behind

Seasonal accounts fail in a specific way. They are created in a hurry, at a merchant you may never use again, with a card number stored because storing it was the default and unchecking the box was three taps further. The password is often a reused one, chosen at a moment when convenience was worth more than hygiene. That merchant then holds a live card, a shipping address, an order history and a credential that opens something else you care about. The exposure is not the merchant's security posture, which you cannot influence. It is the reuse, which you can.

The other seasonal artifact is the shared login: a family streaming plan, a photo service, a warehouse membership, handed around in a text message in December and still circulating in June. Shared credentials are the entries that never get rotated, because rotating one means telling four people, and telling four people is a phone call nobody wants to make. A practiced hand handles these differently, by moving whatever supports it onto proper household or family plans with separate profiles, so that the next change touches one person instead of a group thread.

The pass itself, in the order a fifth pass runs

Start with the compromised-credential report your manager already generates, because that list is the only part of the job with evidence behind it, and work it top down. Then the reused ones, longest-standing first. Then the accounts holding a stored card, where you are deciding whether to delete the card rather than change the password. Then the resets: confirm every high-value account points at an email address you still control and can get into, because a stale recovery address is the failure that turns a ten minute fix into a week of support tickets. Second factor last, on the accounts that would hurt.

What the fifth pass looks like, compared with the first, is shorter and more selective. The first time through, people change everything, which takes a weekend and mostly accomplishes churn. The experienced version leaves the vast majority of entries untouched, because untouched is what the current guidance actually endorses, and spends the saved hour on the four or five accounts where a compromise would cascade: primary email, the phone carrier, the bank, the tax software, the manager's own master credential. Those five get attention every year. The pizza place from 2019 gets deleted.

The protections that exist when something does go wrong

State breach notification laws are the reason you get the letters, and the Federal Trade Commission is the federal body that handles identity theft reporting and recovery planning for consumers. Worth knowing before you need it: credit and debit cards carry different dispute protections, which is a good argument for keeping a credit card as the stored payment method at any merchant you cannot vouch for. A credit freeze at each of the three bureaus is free, reversible, and unrelated to whether your passwords were involved. None of that substitutes for the annual pass, but all of it makes the pass a manageable job rather than an anxious one.

Put the pass on the calendar for the first quiet weekend after the holidays, when the seasonal accounts are still fresh enough to recognize and the card statements have arrived to remind you which merchants you actually used. An hour, once a year, done in the same order each time. The people who find this easy are simply the ones who have done it before.

More from the desk