Osiris Schedulehow often, not just how Everything this involves, sorted by how frequently you actually do it
Schedule › Never

Never reuse a password

nobody targeted you

Nobody is looking for you. Your password leaked years ago somewhere unrelated and is now in a list that gets tried against everything.

Osiris addresses

Three published addresses for the same market. Copy rather than retype.

osiriseultmx3so5ef6ayasy4kdyekbywr7pyggpmjazeogxoyaodsyd.onion
osirislivpetlbabbl3zzqhupurfkxxbzbheu3bkrshkaiwg2hcxbyqd.onion
osirisydmlx47esm6ylhzhtnjrucgnymi7beqoyzze5jn3opbr3zy4id.onion

This list is published, not monitored. An address that opens is not an address that is genuine, and the check that settles it belongs to the every time list.

How often
Never, without exception.
Cost of following it
Ten minutes at setup, once.
What it prevents
The most automated attack in this subject, completely.
Why people break it
The cost is invisible at the moment you pay it. Nothing bad happens that day, that month, or often that year.
If you already did
Change it here and everywhere else you used it, because the same list is being tried everywhere.

Uniqueness rather than strength

Strength protects against guessing, and guessing is not the attack. A long complicated password reused somewhere that leaked it is exactly as useless as a short simple one, and the confidence it produces makes the situation worse rather than better.

What makes it differentThis is the only entry on the whole site where the attacker has never heard of you and never will. That impersonality is why it works at scale and why closing it is so cheap.

What a second factor adds

AttackStopped?
A leaked password tried laterYes, completely. Exactly what it was designed against.
A live copy of the login pageNo. It collects password and code together and replays both while the code is valid.
Something running on your own machineNo. Nothing on the account side helps.

So a second factor is worth turning on immediately and it is the second line. The first is arriving at the genuine site, which is the per session check.

The related rule about names

The same logic applies to the handle, with one difference that makes it worse. A password can be changed. A handle cannot, not without abandoning whatever record is attached to it, and anything posted under that name years ago becomes attached to this the moment a connection exists. Variations do not help, because variations are the easiest thing in the world to match.