webtrajans
en

How to create a strong password you can actually live with

Length beats complexity, uniqueness beats cleverness, and a password manager beats your memory. Here's what current guidance actually recommends.

Updated: 5 min read

Most accounts aren’t hacked by someone cleverly guessing a password. They’re broken into because the password was reused and leaked from another site, was phished, or was short enough to crack once a database was stolen. So a strong password strategy has three parts: make each password long and random, never reuse one, and add a second factor so a stolen password alone isn’t enough.

Length beats complexity

Password strength is about how many guesses an attacker needs. That number grows much faster with length than with character variety:

Password type Example pattern Approx. strength
8 lowercase letters tvqmxrae ~38 bits
8 random characters from all 94 printable ASCII k#9Lq!2v ~52 bits
4 random words (from a 7,776-word list) orbit-cactus-velvet-lamp ~52 bits
6 random words orbit-cactus-velvet-lamp-fjord-mint ~78 bits
16 random characters from all 94 t7&Qm2!vR9#pLx4z ~105 bits

Each extra bit doubles the number of guesses. These figures assume the password is truly random. Human-chosen passwords like Summer2026! look complex but appear in every cracking dictionary, so their real strength is tiny.

Current guidance reflects this. NIST’s Digital Identity Guidelines (SP 800-63B, revision 4, finalised in 2025) say:

  • passwords used as the only factor should be at least 15 characters,
  • sites should allow at least 64 characters and accept spaces and all characters,
  • sites should not force composition rules (one uppercase, one symbol…),
  • sites should not force periodic changes, only changes after a suspected compromise,
  • sites should check new passwords against lists of breached and common passwords.

Passphrases: strong and memorable

For the few passwords you have to type or remember (your computer login, your password manager’s master password), use a passphrase of random words:

copper-ladder-quietly-mango-harbour

The words must be picked randomly, by dice or a generator, not chosen by you, and not a song lyric or famous quote. Five or six words is plenty for a master password. Our password generator can create random passwords or passphrases locally in your browser.

Use a password manager for everything else

Nobody can remember 100 unique 16-character passwords, and you shouldn’t try. A password manager (Bitwarden, 1Password, Proton Pass, or the built-in managers in Apple, Google and Microsoft ecosystems):

  • generates a unique random password for every site,
  • fills it in automatically, and only on the correct domain, which also helps against phishing,
  • syncs across devices, encrypted with a key only you hold,
  • warns you about reused, weak or breached passwords.

Protect the manager itself with a strong passphrase and two-factor authentication, and store recovery codes somewhere safe offline.

Two-factor authentication and passkeys

A second factor means a stolen password isn’t enough on its own. From weakest to strongest:

  1. SMS codes: better than nothing, but vulnerable to SIM-swap fraud.
  2. Authenticator app codes (TOTP): Google Authenticator, Microsoft Authenticator, Authy, or your password manager.
  3. Push approvals: convenient, but beware “approve” fatigue attacks; never approve a login you didn’t start.
  4. Security keys and passkeys: phishing-resistant, because the browser checks the real domain cryptographically.

Turn on 2FA first for your email account: whoever controls your inbox can reset almost every other password. Then banking, your password manager, cloud storage and social media. Where a site offers passkeys, they’re the most convenient and secure option available today.

How websites store your password (hashing)

A well-run site never stores your actual password. It stores a hash: a one-way fingerprint produced by a function designed so you can’t reverse it. When you log in, the site hashes what you typed and compares the results.

  • Fast hashes like MD5 or SHA-256 are fine for checksums but bad for passwords: modern GPUs can try billions of them per second. You can see how they work with our hash generator.
  • Password hashing functions such as Argon2id, bcrypt or scrypt are deliberately slow and memory-hungry, so each guess costs the attacker real time.
  • A random salt per user means two people with the same password get different hashes, so attackers can’t crack everyone at once.

That’s why length matters: if a site’s database is stolen, a long random password stays uncracked even when a short one falls within hours. And it’s why reuse is so dangerous: one badly run site leaks the password you also use for your email.

What to do after a data breach

If a service you use reports a breach, or a breach-alert service flags your email address:

  1. Change the password for that service immediately, using a new random one.
  2. Change it anywhere you reused it. This is where reuse really hurts.
  3. Turn on 2FA if it wasn’t already.
  4. Watch for phishing. Attackers use leaked names and email addresses to send convincing follow-up messages “from” the breached company.
  5. Check account activity such as login history, forwarding rules in email, and saved payment methods.

If financial details were exposed, contact your bank or card provider directly using the number on your card, not a number from an email.

Common mistakes

  • Reusing a “strong” password across sites.
  • Predictable patterns: Password1!, a pet’s name plus a year, keyboard walks like qwerty123.
  • Small variations of an old password (Spring2026! → Summer2026!).
  • Storing passwords in a plain notes app or spreadsheet.
  • Answering security questions truthfully. Treat them as extra passwords and store random answers in your manager.

Checklist

  • A password manager with a strong, unique passphrase as the master password.
  • Every account has its own random password, 16+ characters where allowed.
  • 2FA on email, banking, password manager and social accounts; passkeys where offered.
  • Breach alerts enabled (many managers check against known breach databases).
  • Recovery codes printed or stored safely offline.

Frequently asked questions

How long should a password be?

For accounts protected by a password alone, NIST's 2025 guidance sets a minimum of 15 characters. For important accounts, 16+ random characters or a passphrase of four to six random words is a good target.

Should I change my passwords regularly?

No, not on a fixed schedule. Current NIST guidance says organisations should not force periodic changes; change a password when there's evidence it has been exposed or the service reports a breach.

Are password managers safe?

Reputable password managers encrypt your vault with a key derived from your master password, so the provider can't read it. They are far safer than reusing passwords, as long as you use a strong master password and two-factor authentication.

What is a passkey?

A passkey replaces a password with a cryptographic key pair stored on your device or in your password manager, unlocked with your fingerprint, face or PIN. It can't be phished or reused, and Google, Apple, Microsoft and many sites support it.

Related guides