You know you’re supposed to use different passwords.

You’ve heard the advice. Maybe you’ve tried a password manager. But somewhere between getting it set up, learning how it works, and getting back into an account on another device, you went back to the password you could remember.

That’s the person we built Rosa for.

Conventional password managers are excellent tools. If one already works well for you, keep using it. Rosa exists for the people that advice hasn’t reached in practice. The people whose next password is otherwise going to be the same one again.

We built Rosa to make that habit easier to change. The strongest possible security isn’t its promise. Simplicity is its starting point.

01Ease is part of the point

A security habit has to fit into your life before it can help you.

That doesn’t mean everyone finds password managers difficult. It means some people do, and telling them the software is easy doesn’t remove the things getting in their way. Research with people trying a password manager for the first time has documented exactly these adoption hurdles.1

Rosa starts with something you already know how to do: send a text.

There’s no app to install, no browser extension, no signup form, and no new Rosa username or master password. Text Rosa, ask to save a password part, and open the link in the reply.

You still need to choose your password parts and set the complete password on the website. Rosa makes remembering the different parts easier. It doesn’t change your website passwords for you.

02Give each website something different

When you reuse a password, one exposed login can become a way into other accounts. Attackers automate this: they take stolen email-and-password pairs and try them across other websites. They don’t have to break into your phone to try a password that’s already been stolen.2

Rosa helps you change that pattern with two parts:

01 / With Rosa

A different part
for each website.

You save this part with Rosa.
02 / Only with you

One private part
you remember.

You add this yourself and never give it to Rosa.

Together, they make the password you enter on that website. If the website-specific parts are different, the complete passwords are different. A stolen password from one site won’t simply work unchanged on the others.

That is the practical improvement Rosa is designed to help you make.

The parts still need to be hard to guess. Adding a website’s name to a familiar password creates a predictable pattern. And the private part should be a new secret, not the old password you’ve already used everywhere.

03Yes, we know SMS has risks

SMS is not end-to-end encrypted. People can lose control of their phone number through SIM swapping, and someone with access to their phone or synced messages may be able to read their texts. Those are real risks.3

But a weakness doesn’t make a security measure worthless. CISA recommends MFA over none, while encouraging stronger, phishing-resistant options. SMS can add protection even though it has limits.4

Banks still use it too. Wells Fargo, for example, lists SMS as one way to receive an additional verification code for certain banking actions. That illustrates a familiar tradeoff; it doesn’t establish that Rosa has the same protection as a bank.5

With Rosa, knowing your phone number alone doesn’t let someone read your saved parts. They would need another way in, such as access to your texts, a working Rosa link, or a compromise of the service. That adds an obstacle beyond trying an already-stolen password on another website.

A bank may use a text as an extra check after a password. Rosa uses the text conversation to give you access to your saved parts, without a separate Rosa login. That’s a deliberate convenience tradeoff. Splitting your password doesn’t replace a website’s own two-factor authentication.

04The part you keep matters

When you follow the two-part approach, someone who gets Rosa’s stored part still doesn’t have your complete password.

That’s useful, but it isn’t a guarantee. A weak private part might be guessed. Someone who obtains both a complete password from a website and its matching Rosa part can work out the private part, which you also use elsewhere. Rosa also brings your saved parts together behind one phone number, so losing control of that number can expose more than one of them.

Keep your phone locked, protect your mobile-carrier account, and never forward Rosa’s links. Enter only the website-specific part on Rosa’s page; don’t text either part. Before giving up your number, retrieve what you need and arrange to delete your Rosa data. Use stronger sign-in options on websites that offer them, especially for your email and other important accounts.

Rosa doesn’t ask for your website usernames, name, or email to get started. That keeps the information you entrust to us smaller. It doesn’t make you anonymous: a phone number can often be connected to a person.

05Simple to use still means taking care of the data

Rosa’s save and view pages use encrypted HTTPS connections. Saved parts are encrypted in storage. Links use securely generated random codes, expire after ten minutes, and permit only the save or view you requested. The pages where you enter and retrieve parts load no advertising or analytics scripts.

These protections have specific jobs. They don’t make SMS encrypted, and Rosa’s systems can read the stored parts to return them to you. The private part you keep out of Rosa remains important. Our privacy policy explains the data handling in more detail.

06A habit you can start

Rosa is built around a practical question: how do we help someone stop using the same password everywhere when the tools they’ve tried haven’t stuck?

Our answer is a familiar text conversation, different password parts for different websites, and one private part you keep to yourself.

If that fits your life, your next password can be different.

Text “hello” to Rosa

1-864-777-8711

For US and Canadian mobile numbers. Message and data rates may apply. Message frequency varies. Text HELP for help or STOP to opt out. Terms · Privacy.

Sources & further reading

  1. A study of novice password-manager users ↗
  2. How credential stuffing works ↗
  3. The FTC’s explanation of SIM swapping ↗
  4. CISA’s MFA guidance ↗
  5. Wells Fargo Advanced Access ↗