How to Create a Strong Password You Can Actually Use
Weak, reused passwords are behind a huge share of account breaches. The good news is that a genuinely strong password is not about cramming in symbols you will never remember — it is mostly about length and unpredictability, both of which are easy to get right.
What makes a password strong
Strength comes from how many guesses an attacker would need. That depends on length and how random the characters are. A longer password from a larger pool of characters has astronomically more combinations. This is measured as entropy — more entropy means harder to crack.
Length beats complexity
A 16-character password made of random words is far stronger than an 8-character jumble of symbols, and much easier to type. A passphrase like four unrelated random words strung together can be both memorable and extremely strong. Where a site allows it, longer is almost always better.
Rules worth following
- Use at least 12–16 characters; more for important accounts.
- Never reuse a password across sites — one breach then exposes many accounts.
- Avoid names, birthdays, common words and keyboard patterns like 'qwerty'.
- Mix character types if the site requires it, but prioritise length.
- Turn on two-factor authentication wherever it is offered.
How to manage many passwords
Nobody can remember a unique strong password for every account, and you should not try. A reputable password manager generates and stores them securely, so you only remember one strong master password. This is the single biggest practical upgrade most people can make to their online security.
How attackers actually crack passwords
It helps to know what you're up against, because it's rarely a person sitting there typing guesses. Attackers run software that tries billions of combinations a second, and they start with the obvious: leaked password lists from old breaches, dictionary words, names, dates and predictable swaps like 'P@ssw0rd'. If your password has ever turned up in a breach — even on a completely different site — it's already on those lists. That's the real reason reuse is so dangerous: one company's leak quietly hands over the key to every account where you used the same password.
Passphrases: strong and actually memorable
The secret to a password you can remember but a computer can't guess is to go long and random rather than short and cryptic. Four unrelated random words — something like 'copper-violin-mantis-harbor' — is genuinely hard to crack thanks to its length, yet far easier to recall than 'X7#kq2!z'. The important word is random: a famous quote or song lyric doesn't count, because those are in the attackers' lists too. Wherever a site allows length and spaces, a passphrase is often the sweet spot.
Two-factor authentication is your safety net
Even a perfect password can leak. Two-factor authentication adds a second step — a code from an app, or a physical key — so a stolen password alone isn't enough to get in. App-based codes beat SMS, which can be intercepted, but any 2FA is far better than none. Switch it on for your email first: whoever controls your email can reset the password to almost everything else you own.
Frequently asked questions
How long should a password be?
Aim for at least 12–16 characters, and go longer for important accounts like email and banking. Length does more for security than any single fancy symbol.
Do I really need a different password for every site?
Yes — it's the single most important rule. Reuse means one breach unlocks many accounts. A password manager makes unique passwords effortless, because you only have to remember one master password.
Are password managers actually safe?
Reputable ones encrypt your vault so even the provider can't read it, and the gain from having unique, strong passwords everywhere far outweighs the small risk. For most people it's the biggest practical security upgrade available.
The bottom line
Strong passwords are long, random and never reused — and a password manager makes living that way effortless. Generate fresh, high-entropy passwords with our in-browser tool, which keeps everything on your device.