← The Journal · Independent Operations
Why Independent Authors Have So Many Passwords
Every new channel arrives with an account, a verification method, a dashboard, and another way to be locked out of your own work.
By Kevin Snell
Every new channel creates an account, and every account creates another way into the business.
Independent authors collect passwords because modern publishing is not one system. It is a chain of systems that happen to produce and sell books. Retailers, distributors, domains, websites, email platforms, payment processors, advertising accounts, cloud storage, design tools, printers, audiobook services, and tax portals each want a login. Some want two.
The inconvenience is comic until access fails. Then the account is not merely another website. It may control the domain, the customer list, the royalty deposit, or the only current copy of a production file. Password management is therefore not personal tidiness. It is continuity planning for a very small business.
Reuse turns convenience into shared risk
Using the same memorable password across accounts makes the collection easier to remember and easier to compromise. If one service exposes or accepts that credential, an attacker can try it elsewhere. NIST recommends a password manager, multifactor authentication, and passwords of at least fifteen characters when a password must be created by the user.[1] CISA likewise advises small businesses to use password managers, unique passwords, MFA, and tested backups.[2]
A password manager does not remove risk. It concentrates the work into protecting one vault well: a strong master passphrase, MFA, recovery information stored safely, and devices that are themselves secured. That is still a better system than a document called PASSWORDS FINAL 3 or a familiar phrase reused across every account that pays the author.
MFA needs its own recovery plan
Multifactor authentication is valuable because a stolen password alone is no longer enough. It also creates a second dependency. If the author loses the phone, changes numbers, deletes an authenticator, or cannot access an email account, the security control can become an access problem.
Recovery codes should be generated, labeled, and stored somewhere separate from the device used for authentication. Critical accounts should have current recovery addresses and, where supported, more than one secure authentication method. “I turned on MFA” is not a complete plan unless the author also knows how to recover from the loss of the factor.
Know which accounts can hurt the most
Not every login deserves equal anxiety. The domain registrar, primary email account, password manager, payment services, retailer dashboards, cloud storage, and website administration usually form the critical tier. Losing one of those can expose or lock access to several others.
The author should know which email address owns each account, who controls billing, where recovery codes live, and whether another trusted person could obtain necessary access during an emergency. This is especially important when collaborators manage a site or advertising account. Convenience should not leave the author’s business permanently attached to someone else’s personal login.
Fewer systems create fewer doors
Password overload can also reveal unnecessary complexity. An abandoned newsletter service, duplicate analytics tool, unused retailer account, or expired design platform remains another place where payment details, files, or personal information may persist. Closing what is no longer used is part of maintenance.
The goal is not to remember more passwords. It is to make memory irrelevant: unique credentials in a manager, strong MFA, tested recovery, clear ownership, and fewer accounts that exist only because a tool once looked useful. Independent authors have many passwords because they operate many systems. They need a system for the passwords for exactly the same reason.
Sources
1. NIST, “How Do I Create a Good Password?” (updated 2025)
Reader comments
Loading comments…
