How to Create a Strong Password (and Actually Remember It)

Most accounts are not hacked by genius hackers guessing clever passwords. They are taken over because people reuse the same weak password everywhere, and one leaked database unlocks everything. Creating strong passwords is easier than it sounds once you know what actually matters.

What makes a password strong?

A strong password is long, random and unique.

  • Long: every extra character multiplies the number of possible combinations. Length matters more than anything else.
  • Random: no names, birthdays, pets, football teams or keyboard patterns like “qwerty123”. Attackers try these first.
  • Unique: a different password for every account, so one breach does not open the others.

How long should a password be?

Password strength is measured in bits of entropy: how many guesses an attacker would need. Rough guide for randomly generated passwords:

Length and characters Entropy Verdict
8 characters, lowercase only about 38 bits Weak
8 characters, mixed with symbols about 52 bits Fair
12 characters, mixed about 79 bits Strong
16 characters, mixed about 105 bits Very strong

Aim for at least 12 characters for everyday accounts and 16 or more for email, banking and anything work-related. Our password generator shows the entropy of every password it creates.

Why password reuse is the biggest risk

Data breaches happen all the time, and leaked email-and-password lists are shared and sold. Attackers then try those same combinations on email, banking, shopping and social media sites. This is called credential stuffing, and it is automated. If you reuse passwords, one small site’s breach can hand over your email account, and your email account can reset every other password you have.

Method 1: Random passwords + a password manager (best)

  1. Install a password manager: Bitwarden (free), 1Password, or the one built into your browser or phone.
  2. Create one strong master passphrase that you memorise (see Method 2).
  3. For every account, generate a random 16+ character password and let the manager save it.
  4. Let the manager fill passwords in for you, on your computer and phone.

You only remember one thing, and every account gets a unique, uncrackable password.

Method 2: Passphrases you can remember

For the few passwords you must type from memory, such as your master password or computer login, use a passphrase of four or more random words:

copper-lantern-river-mango-47

It is long, easy to type, easy to remember and very hard to guess, as long as the words are truly random rather than a famous quote or song lyric. Adding a number or symbol between words makes it even stronger.

Turn on two-factor authentication

Two-factor authentication (2FA) adds a second step, such as a code from an authenticator app, a passkey or a security key. Even if someone steals your password, they cannot log in without it. Turn it on for email first, then banking, social media and cloud storage. Prefer an authenticator app over SMS where possible.

What about passkeys?

Passkeys let you sign in with your fingerprint, face or device PIN instead of a password, and they cannot be phished. Google, Apple, Microsoft and many popular sites support them. Where passkeys are offered, they are an excellent choice. You will still need passwords for many sites for years to come.

Password mistakes to stop today

  • Using the same password on more than one site.
  • Adding “1” or “!” to an old password when forced to change it.
  • Storing passwords in a notes app, email or unprotected spreadsheet.
  • Sharing passwords over WhatsApp or email. For Wi-Fi, share a WiFi QR code instead.
  • Ignoring breach warnings from your browser or password manager.

Quick action plan

  1. Install a password manager.
  2. Create a strong master passphrase.
  3. Change your email password to a unique 16+ character one and enable 2FA.
  4. Work through your important accounts, replacing reused passwords with generated ones.