Use a different strong password for each account. A reputable password manager can help generate and store them; arrange setup and recovery with a trusted adult. Multifactor authentication adds a different kind of proof. Keep recovery codes private and do not approve a sign-in you did not start.
Worked example
Two accounts with the same password share a weakness: one exposed password may be tried on both. Making both passwords longer but still identical does not remove reuse.
Three Fictional Account Labels
The table uses labels, not passwords. Account A and Account B use the same secret, labeled SAME. Account C has its own different secret, labeled UNIQUE. A sign-in request arrives for C even though its owner did not start one. These labels must never be used as real passwords. Nobody should type a real password or recovery code into this exercise.