Password advice usually pretends sharing never happens: every credential is personal, secret, and known to exactly one brain. Reality disagrees. Households share streaming logins and Wi-Fi keys. Couples share bank access. Small teams share the company Instagram, the domain registrar, the shipping account. Colleagues go on vacation and hand over the keys. The question isn't whether people share passwords - Surveys consistently find a large majority do - It's whether they share them in ways that don't leak.
Most people share the worst way possible: typed straight into a text message or email. This guide ranks the common methods from dangerous to solid, shows you the safe patterns for the three big scenarios (family, Wi-Fi, work), and covers the part everyone forgets - Taking access back.
Why texting a password is worse than it feels
When you text or email someone a password, you're not sending it so much as publishing it to a small archive. That plaintext string now lives:
- in your sent messages and their inbox, indefinitely and searchably
- in both phones' cloud backups
- synced across every device either of you logs into
- on the provider's servers, subject to their retention and any future breach
- in whatever apps have notification or backup access on either phone
Neither of you will ever delete all those copies; most people delete none of them. Anyone who later gets into either mailbox - And mailbox takeovers are among the most common account compromises - Can simply search "password" and harvest years of shared credentials. Phishers do exactly this after a successful mailbox phish, which is one more reason to be fluent in spotting password-stealing scams.
The subtler problem: a password pasted into chat is now outside any system that can revoke it. You can't expire a text message.
The ranking: every sharing method from worst to best
| Method | Copies left behind | Revocable? | Verdict |
|---|---|---|---|
| Email or SMS/chat, in plaintext | Many, on both ends + servers | No | Avoid |
| Sticky note / whiteboard | Physical, visible to anyone present | No | Avoid |
| Phone call (spoken) | None recorded (usually) | No | OK for low-stakes, error-prone |
| Split channels (half by chat, half by call) | Partial fragments | No | Decent one-off fallback |
| Encrypted messenger with disappearing messages | Few, time-limited | Partially | Acceptable one-off |
| One-time self-destructing link | One, destroyed on read | Link expires | Good for one-offs |
| Encrypted file/text, key shared separately | Ciphertext only | Re-key anytime | Good, more effort |
| Password manager shared vault | Encrypted, managed | Yes, cleanly | Best |
The pattern behind the ranking: the best methods minimize plaintext copies, separate the secret from the channel, and - The gold standard - Support revocation.
Best practice: manager-based sharing
Every mainstream password manager now does sharing properly. Bitwarden has organizations and collections (including free two-person sharing), 1Password has shared family and team vaults plus one-off share links, and Apple's iCloud Keychain added shared password groups. The mechanics matter: shared items stay encrypted end to end, both sides always see the current version when someone updates the password, and removing a person from the vault is a two-click operation followed by a rotation.
This solves the three chronic problems of informal sharing - Stale copies ("wait, you changed it?"), plaintext sprawl, and un-revocable access. If your household or team shares more than a couple of credentials and you're not using a manager yet, sharing alone justifies one; our password manager guide compares the free and paid options without the affiliate-link cheerleading.
For couples and families there's a bonus: shared vaults are quiet emergency planning. If one partner is hospitalized, the other can pay the bills without archaeology through drawers and inboxes.
Good one-off options when a vault is overkill
Sometimes you need to send one credential to one person once - A contractor, a relative, a colleague at another company. Three sound patterns:
One-time secret links. Tools built for this (self-hosted or hosted "one-time secret" services) store the secret encrypted, give you a link, and destroy the secret the moment it's viewed - So a later mailbox compromise finds only a dead link. Send the link by email and, ideally, tell the recipient out-of-band what it is. If the link arrives already-viewed, you know something intercepted it: that's a feature.
Encrypt it yourself. Paste the credential into a browser-based AES-256 encryption tool, encrypt it with a key you share through a different channel (say the ciphertext goes by email, the key by phone call), and the email trail contains only ciphertext. This is the classic "separate the lock from the key" pattern and works with zero special software on the recipient's side beyond the same tool.
Split channels. No tools at all: read half the password over a phone call, send the other half by message. Neither channel alone contains the secret. It's clunky and unrevocable, but vastly better than the whole string in one text.
The Wi-Fi special case
Wi-Fi is the password people share most and think about least. You want guests on your network without friction - You just don't want the key living in a hundred phones forever. The clean setup:
- Use a QR code. Modern phones join a network from a scanned QR code without ever displaying the key. Generate a strong WPA2/WPA3 key and a printable QR card in one step with a WiFi password generator, and stick the card on the fridge - Guests scan, nobody types, nobody screenshots.
- Run a guest network. Nearly every router supports an isolated guest SSID. Guests reach the internet, not your laptops, printers and cameras. Rotate the guest key occasionally; your main network's key can then stay stable and strong.
- Rotate on departures. Housemate moved out? Contractor finished? The Wi-Fi key they know should change, same as any shared credential.
Sharing at work: rules that survive turnover
Work sharing adds two hazards: turnover and impersonation. A few rules cover most of it:
- Shared credentials live only in shared vaults - Never in spreadsheets, wikis, or a channel called #logins. The vault's access list is your record of who knows the secret.
- Prefer real multi-user access over sharing. Many services support multiple seats, roles or delegated access (email delegation, social media roles, cloud IAM). A password shared by five people can't tell you who logged in; five accounts can.
- Offboarding = rotation. When someone leaves, every credential they could see gets changed. With vault-based sharing this is a checklist, not a scavenger hunt. The trigger-based logic - Rotate on events, not calendars - Is the same one behind how often you should change your password.
- Beware the "urgent password request." A message that says "boss needs the login NOW" is a social-engineering staple. Verify on a second channel before sharing anything, no matter how senior the requester appears.
Before you share a password, know how you'll un-share it. If a method gives you no way to revoke or rotate, you're not sharing the password - You're giving it away.
Revocation: the forgotten half of sharing
Every share should end one of two ways: the need ends and you rotate the password, or the share was open-ended and you review it periodically. When access should end - Breakup, moved-out roommate, finished contract, resignation - Deleting the message you sent does nothing; the recipient has the string. The only real revocation is changing the password itself, and if the account matters, checking its active sessions and connected devices afterward. Make the replacement a fresh, fully random one - The strong password guide covers what "strong" means in practice - And if the credential is still shared with others, update it in the shared vault so everyone silently gets the new version.
And for accounts that support it, add two-factor authentication: it converts "someone still knows the old password" from an incident into a non-event.
FAQ
What's the safest way to share a password with a family member?
A password manager's shared vault or family plan: items stay encrypted end to end, everyone always sees the current version, and you can remove access cleanly later. Apple's shared password groups, Bitwarden's free two-person organization, and 1Password Families all do this well. For a one-off, a one-time self-destructing link beats any text message.
Is it safe to share passwords over WhatsApp or Signal?
End-to-end encryption protects the message in transit, which puts these well above SMS or email. The remaining problem is at rest: the password sits in both chat histories and backups indefinitely. If you must use a messenger, turn on disappearing messages, delete the message on both ends after use, and rotate the password when the need ends.
How do I share my Wi-Fi password with guests without revealing it?
Use a QR code: phones can join a network by scanning it, without the key ever being displayed or typed. Pair that with a guest network on your router so visitors are isolated from your own devices, and you can hand out access freely while your main network's key stays private.
Is sharing a Netflix or streaming password dangerous?
The password itself is usually low-stakes - The danger is reuse. If your streaming password is also your email or banking password, sharing it hands over those accounts too. Make the shared password unique to that service, share it through a vault rather than a text, and change it when someone leaves the household pool.
How do I take back a password I already texted to someone?
You can't un-send knowledge - Deleting the message doesn't help. Change the password on the account, then sign out other sessions and review connected devices from the account's security page. Going forward, use revocable methods (shared vaults, one-time links) so ending access is an administrative click instead of an emergency.