Quick answer: a strong password is long, random and used for one account only. Aim for at least 12 to 16 random characters, let a password generator create it, and store it in a password manager so you never have to remember it.

Why Length Matters More Than Complexity

Attackers guess passwords by trying enormous numbers of candidates. Every extra character multiplies the number of candidates they must try. Security people measure this in bits of entropy: each character chosen at random from a pool of N possibilities adds log2(N) bits, and every extra bit doubles the guesses needed.

  • 8 random lowercase letters: about 38 bits.
  • 16 random characters from uppercase, lowercase, digits and symbols: roughly 100 bits, which is beyond the reach of any realistic guessing attack.

That is why a long password made of ordinary characters beats a short one stuffed with symbols.

Random Beats Clever

These figures only hold when the password is genuinely random. Substitutions such as P@ssw0rd!, keyboard patterns, birthdays, pet names and song lyrics are exactly what cracking tools try first, so they are far weaker than they look. Humans are poor random number generators; a browser's cryptographic random source is not.

Five Habits That Protect Your Accounts

  1. Make it long. 12 to 16 characters is a sensible minimum, and longer for your email and password manager.
  2. Make it random. Generate it instead of inventing it.
  3. Use it once. If one site is breached, reused passwords let attackers walk into your other accounts.
  4. Use a password manager. It remembers hundreds of unique passwords so you do not have to.
  5. Turn on two-factor authentication. It protects an account even if the password leaks.

What About Passwords You Must Remember?

For the few passwords you cannot store, such as your password manager's master password or your device login, use a passphrase: four to six unrelated words chosen at random. Picking words from a list of 7,776 (as in the Diceware method) gives about 12.9 bits per word, so five words is roughly 65 bits and six is about 78 bits. The key word is random: a quote or a phrase from a book is not.

Common Mistakes

  • Adding a number to the end of an old password when a site forces a change.
  • Reusing your email password anywhere else. Email resets every other account.
  • Saving passwords in a notes app or a spreadsheet without encryption.
  • Sending passwords in chat or email. Share access through your manager instead.

Current guidance from NIST favors length and screening against known-breached passwords over forced complexity rules, and advises against routine periodic changes unless there is evidence of a compromise.