My old boss swore by password reuse, until a breach proved him wrong in 90 minutes
I worked for a guy named Dave in Atlanta who told me that using the same password for everything was fine, that nobody would ever target us. I believed him for two years, then his personal email got hit in a data breach from a forum he joined back in 2019. Within 90 minutes, someone used that same password to get into our company VPN and tried to wire money out of our client account. We caught it because of a two-factor alert, but Dave still insisted it was a one-off and I was overreacting. So which is it, has anyone else had a manager or mentor give advice that you knew was shaky, did you push back or just quietly add a password manager behind their back?
Watched the same thing happen with my old manager at a staffing firm, except we did not catch it in time and it cost us two days of cleanup. Push back once, respectfully, with the actual story so there is a paper trail if it blows up later. Then just quietly protect yourself, set up your own password manager, turn on 2FA everywhere you can, and never reuse your work login on anything personal. The hard part is you cannot fix a guy like Dave, he has to get burned himself before it clicks. Cover your own accounts, document what you warned him about, and keep your resume warm in case the next breach is the one that actually costs the company money.