{"id":241221,"date":"2026-05-19T20:30:47","date_gmt":"2026-05-19T20:30:47","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/19\/how-using-a-password-manager-can-protect-points-and-miles-the-points-guy\/"},"modified":"2026-05-19T20:30:47","modified_gmt":"2026-05-19T20:30:47","slug":"how-using-a-password-manager-can-protect-points-and-miles-the-points-guy","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/19\/how-using-a-password-manager-can-protect-points-and-miles-the-points-guy\/","title":{"rendered":"How using a password manager can protect points and miles &#8211; The Points Guy"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Maximizing loyalty programs and credit card rewards have taken me to more than 60 countries in my lifetime, and I&#8217;ve tried just about every tip out there \u2014 using <span><a href=\"https:\/\/thepointsguy.com\/loyalty-programs\/current-transfer-bonuses\/\" target=\"_blank\" rel=\"noopener\">transfer bonuses<\/a><\/span>, snagging cards with <span><a href=\"https:\/\/thepointsguy.com\/credit-cards\/limited-time-card-offers\/\" target=\"_blank\" rel=\"noopener\">limited-time welcome offers<\/a><\/span>, <span><a href=\"https:\/\/thepointsguy.com\/loyalty-programs\/points-and-miles-double-dipping\/\" target=\"_blank\" rel=\"noopener\">double- or triple-dipping<\/a><\/span>, and even mattress and mileage running.<\/p>\n<p>But one of my strategies is nowhere near as exciting \u2014 though it&#8217;s arguably more important than all of those things put together.<\/p>\n<p>And it is&#8230;drumroll&#8230;a password manager.<\/p>\n<p>Here&#8217;s why you should be using one of these tools to protect your hard-earned rewards.<\/p>\n<h2 class=\"jsx-2362441780\">What is a password manager, and why should you use one?<\/h2>\n<figure class=\"jsx-3874346954 tpg-figure\">\n<div style=\"padding-top:0\" class=\"jsx-2453190082 full-width-auto-height-image\"><\/div><figcaption class=\"jsx-3874346954 figcaption\">SKAMAN306\/GETTY IMAGES<\/figcaption><\/figure>\n<p>In essence, password managers serve as a secure repository to save your login credentials across various websites and mobile apps. In addition, they can help generate new passwords when you&#8217;re setting up a new account \u2014 or updating an existing one. This helps ensure you have a unique, hard-to-guess password for each of your accounts.<\/p>\n<p>Some of you may have a &#8220;favorite&#8221; password that&#8217;s easy for you to remember, and because of that, you use it across all of your accounts (no judgment \u2014 I was there once). Unfortunately, this makes you incredibly vulnerable to a hack. After all, if that one password makes it to the dark web, a hacker could gain access to not just one but <em>all <\/em>of your accounts.<\/p>\n<p>For example, let&#8217;s say you set the password on your favorite frequent flyer account to be P@ssw0rd. While this may satisfy the password requirements of said program (since it includes a capital letter, a number and a special character), it&#8217;s far from secure. In fact, a <span><a href=\"https:\/\/nordpass.com\/most-common-passwords-list\/\" target=\"_blank\" rel=\"noopener\">2025 study<\/a><\/span> from VPN provider NordPass found that this ranked 15th on a list of the most commonly used passwords across the globe. The most common? 123456 \u2014 with over 21.6 <em>million <\/em>instances.<\/p>\n<p>If hackers can find your account number, they can try various password combinations to gain access.<\/p>\n<p>However, a password manager can make this nearly impossible.<\/p>\n<div class=\"EmailSignUp_container__YVxAW tw-border tw-border-gray-2\"><picture class=\"tw-flex tw-items-center tw-justify-center tw-opacity-0\"><source media=\"(max-width: 767px)\" srcset=\"\/images\/EmailSignUp\/daily-mob.svg\"\/><img decoding=\"async\" alt=\"\" src=\"https:\/\/thepointsguy.com\/images\/EmailSignUp\/daily-dt.svg\"\/><\/picture>\n<div class=\"EmailSignUp_form__xvcP4\">\n<p>Reward your inbox with the TPG Daily newsletter<\/p>\n<p>Join over 700,000 readers for breaking news, in-depth guides and exclusive deals from TPG\u2019s experts<\/p>\n<form class=\"jsx-881693933 newsletter-form\">\n<div class=\"jsx-881693933 EmailCapture_confirmation__AJ4nI EmailCapture_noCheckbox__2BHzb   &#10;          \">\n<p class=\"tw-text-xs-regular !tw-text-gray-5 hover:!tw-text-gray-5 tw-max-w-lg\">By signing up, you will receive newsletters and promotional content and agree to our<!-- --> <a class=\"!tw-text-gray-5 hover:!tw-text-gray-5\" href=\"https:\/\/thepointsguy.com\/terms-of-use\/\" target=\"_blank\" rel=\"noopener\">Terms of Use<\/a> <!-- -->and acknowledge the data practices in our<!-- --> <a class=\"!tw-text-gray-5 hover:!tw-text-gray-5\" href=\"https:\/\/thepointsguy.com\/privacy-policy\/\" target=\"_blank\" rel=\"noopener\">Privacy Policy<\/a>. You may unsubscribe at any time.<\/p>\n<\/div>\n<\/form>\n<\/div>\n<\/div>\n<p>I personally use LastPass to secure my passwords, and while writing this section, I asked it to generate a new, unique password \u2014 16 characters long, with lowercase and uppercase letters, numbers and randomized symbols. Here&#8217;s what it came back with:<\/p>\n<p>Hh6BAuXP#OvryiA#<\/p>\n<p>The chance of a hacker guessing this or even a brute-force computing effort uncovering it is quite small. In fact, using the above parameters gives over 37 <em>nonillion <\/em>possible combinations (that&#8217;s 37 with thirty zeroes afterward).<\/p>\n<p>Of course, there&#8217;s very little chance that I could remember this password myself \u2014 which is where the repository feature comes in. All of my unique, hard-to-guess passwords are saved seamlessly inside my LastPass vault. When I need to log in from a trusted device, the password is populated automatically.<\/p>\n<h2 class=\"jsx-2362441780\">Why is this so important for loyalty programs?<\/h2>\n<p>A password manager can help secure all of your accounts, but there are some key reasons why loyalty programs are so vulnerable. For starters, these programs don&#8217;t offer published or legal protections, a notable contrast to credit cards, where the <span><a href=\"https:\/\/thepointsguy.com\/credit-cards\/fair-credit-billing-act-guide\/\" target=\"_blank\" rel=\"noopener\">Fair Credit Billing Act<\/a><\/span> caps your liability for unauthorized charges at $50. Many issuers go even further, offering $0 fraud liability for unauthorized purchases.<\/p>\n<p><strong>Related: <span><a href=\"https:\/\/thepointsguy.com\/news\/credit-card-fraud-story-save-thousands-dollars\/\" target=\"_blank\" rel=\"noopener\">How a 10-minute call reversed $2,300 in fraudulent charges on my credit card<\/a><\/span><\/strong><\/p>\n<p>That&#8217;s not the case with most loyalty programs.<\/p>\n<p>As an example, here&#8217;s an excerpt from the terms and conditions for a major airline&#8217;s program:<\/p>\n<blockquote><p>&#8220;[Airline name] assumes no responsibility for and is not liable for any unauthorized access by third parties to a member&#8217;s account or account information, including any unauthorized award transaction made from the account, except as provided under applicable laws. [Airline name] assumes no obligation or duty to re-credit any unauthorized mileage withdrawal made by third parties; however, [Airline name] reserves the right to review, in its sole discretion, requests for re-crediting unauthorized mileage withdrawals provided such request is made to [Airline name] within three months of the unauthorized withdrawal.&#8221;<\/p><\/blockquote>\n<p>In addition, many of these programs don&#8217;t require two-factor authentication \u2014 or even have it as an option.<\/p>\n<p>To test this, I attempted to log in to six popular airline programs and four top hotel loyalty programs from a private window in a browser I&#8217;d never used before.<\/p>\n<div class=\"tw-my-8 tw-overflow-x-auto sm:tw-overflow-visible\">\n<table class=\"tw-w-full tw-min-w-[640px] sm:tw-min-w-0 tw-table-auto\" style=\"-webkit-overflow-scrolling:touch\">\n<thead>\n<tr>\n<th class=\"tw-bg-gray-6 tw-p-4 tw-text-md-medium tw-font-semibold tw-text-white tw-text-left first:tw-rounded-tl-lg last:tw-rounded-tr-lg tw-pl-3\" scope=\"col\"><strong>Program<\/strong><\/th>\n<th class=\"tw-bg-gray-6 tw-p-4 tw-text-md-medium tw-font-semibold tw-text-white tw-text-left first:tw-rounded-tl-lg last:tw-rounded-tr-lg\" scope=\"col\"><strong>Two-factor authentication?<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">Text message to confirm<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">Choice of text or email to confirm<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">None<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">Email to confirm<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">None<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">Text message to confirm<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">None<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">None<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">Choice of text or email to confirm<\/span><\/p>\n<\/td>\n<\/tr>\n<tr class=\"tw-relative even:tw-bg-gray-1\">\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\"\/>\n<td class=\"tw-text-md-regular tw-p-4 tw-pb-3 tw-align-top tw-h-auto\">\n<p><span class=\"tw-break-words\">None<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>At the time of writing, only half required an additional verification step.<\/p>\n<p>I tried the exact same thing with my accounts across seven credit card issuers, and all of them required two-factor authentication, either immediately upon logging in or when clicking into the redemption options.<\/p>\n<p>Finally, once inside your account, hackers can quickly burn your rewards on cash-equivalent redemption options or last-minute travel bookings, in the hopes that you won&#8217;t notice the hack until it&#8217;s too late \u2014 which is exactly what happened to multiple TPG staffers in recent years.<\/p>\n<p>Principal spokesperson Clint Henderson <span><a href=\"https:\/\/thepointsguy.com\/news\/hacked-aadvantage-account\/\" target=\"_blank\" rel=\"noopener\">had his AAdvantage account hacked<\/a><\/span> in 2024, with nearly 400,000 miles burned for last-minute rental cars. Later that year, senior editor Gabrielle Bernardini had a <span><a href=\"https:\/\/thepointsguy.com\/news\/southwest-rapid-rewards-account-hacked\/\" target=\"_blank\" rel=\"noopener\">hacker use over 17,000 points<\/a><\/span> from her Southwest Rapid Rewards account for a hotel for a last-minute hotel stay. And just a few weeks ago, managing editor Ben Mutzabaugh received a preemptive notification that a hacker was trying to use his American miles for gift cards \u2014 though thankfully, this was caught before his account was drained.<\/p>\n<p>While both Clint and Gabby had their balances restored, each one required some significant time to do so.<\/p>\n<h2 class=\"jsx-2362441780\">Bottom line<\/h2>\n<p>There are few things more frustrating in the world of points and miles than a hacker using your rewards. Thankfully, there are steps you can take to secure your account \u2014 including the use of unique, hard-to-guess passwords for every one of them. And a password manager can play an important role in saving these credentials so you don&#8217;t have to remember long strings of seemingly random characters.<\/p>\n<p>Of course, this isn&#8217;t a foolproof solution, as hackers may still find a way to gain access. Nevertheless, it&#8217;s an important step to add an additional layer of security to your loyalty program accounts, especially since our tests show that several popular loyalty programs don&#8217;t use two-factor authentication.<\/p>\n<p>If you&#8217;re not currently using a password manager, I&#8217;d strongly encourage you to do so \u2014 right now. Otherwise, those points and miles may not be there when you really need them.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thepointsguy.com\/travel\/maximizing-rewards-with-password-manager\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Maximizing loyalty programs and credit card rewards have taken me to more than 60 countries in my lifetime, and I&#8217;ve tried just about every tip out there \u2014 using transfer bonuses, snagging cards with limited-time welcome offers, double- or triple-dipping, and even mattress and mileage running. But one of my strategies is nowhere near as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":241222,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":{"0":"post-241221","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-travel"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/241221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=241221"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/241221\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/241222"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=241221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=241221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=241221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}