What makes a password strong

A strong password is one that takes a computer a very long time to guess, even with software designed to try millions of combinations per second. The three things that matter are length, variety, and avoiding words that appear in dictionaries or common password lists.

Length is the single most important factor. A 12-character password is exponentially harder to crack than an 8-character one, even if both use only letters. Most accounts now let you use 16 characters or more, and you should use that space. A password like correct-horse-battery-staple (28 characters, all lowercase) is far stronger than Tr0pic@l! (9 characters, mixed case and symbols), even though the second one looks more complicated.

Variety means using uppercase letters, lowercase letters, numbers, and symbols. A password with all four types is harder to crack than one with only two types, but only if the length is also there. The combination of length and variety is what creates real protection.

Key Takeaways

  • Make your password at least 12 characters long, and 16 or more if the site allows it, because length matters more than complexity.
  • Use a mix of uppercase letters, lowercase letters, numbers, and symbols to increase the number of possible combinations.
  • Avoid dictionary words, names, birthdays, and sequences like 123456 or qwerty, because password-cracking software tests these first.
  • Use a different password for each account that matters — email, banking, social media — so one breach does not expose everything.
  • A password manager stores long, random passwords securely so you only have to remember one master password.

How to build a password from scratch

Start with a base that is not a real word. One method is to take a phrase you will remember and use the first letter of each word, then add numbers and symbols. For example, "My dog ate three socks on Tuesday" becomes MdAt3SoT!. This is 10 characters and uses all four types, but it is still relatively short.

A better approach is to use the whole phrase but modify it slightly. "My dog ate three socks on Tuesday" could become MyDog-Ate3Socks-OnTuesday! (26 characters). This is long, uses all four types, and is not a phrase that appears in any dictionary. You can remember it because it is based on something meaningful to you, but it is not something a person who knows you could guess.

Another method is to string together random words that have nothing to do with each other. Purple-Elephant-Keyboard-Napkin-47 (35 characters) is straightforward to remember because the words are vivid, but the combination is random enough that no dictionary will contain it. Add a symbol or two if the site requires it: Purple-Elephant-Keyboard-Napkin-47!.

What to avoid

Do not use your name, your child's name, your pet's name, or your birthday in any form. These are the first things someone who knows you will try, and they are also the first things password-cracking software tests. The same goes for your username, your email address, or the name of the website itself.

Do not use common sequences like 123456, qwerty, abcdef, or 111111. These appear in every password dictionary and will be tested in the first second of a crack attempt. Do not use patterns like 1q2w3e or keyboard walks where you move your finger across the keyboard in order.

Do not reuse the same password across multiple accounts. If one website is breached and your password is exposed, a criminal will try that same password on your email, your bank, your social media, and everywhere else. A unique password for each account means a breach at one site does not compromise the others.

Using a password manager to handle the complexity

If you have more than three or four accounts that matter — email, banking, work, social media — remembering unique strong passwords for each one becomes impractical. This is where a password manager solves the problem. A password manager is software that stores your passwords in an encrypted vault and fills them in automatically when you visit a website.

The password manager generates random passwords for you, so you do not have to invent them. A generated password might look like 7kR#mQ$vL2pX@9wN — completely random, 16 characters, all four types. You do not need to remember it. The password manager remembers it and enters it for you.

You only have to remember one strong password: the master password that unlocks the password manager itself. This means you can afford to make that one password very long and complex, because you only have to type it once per session. Common password managers include Bitwarden, 1Password, LastPass, and Dashlane. Most have free versions that work across your phone and computer.

Testing your password strength

Several websites let you test how long it would take to crack a password. You type the password into the site, and it tells you the estimated time. Sites like How find Is My Password or Password Strength Checker will show you whether your password would take seconds, hours, years, or centuries to crack.

These testers do not store your password — they run the calculation in your browser and discard it when ready. Even so, do not test a password you actually use. Test a similar password, or test one you have already changed. The point is to understand whether your approach (length, variety, randomness) is strong enough.

If a tester says your password would take only hours or days to crack, make it longer. Add four more characters, or switch to a longer phrase. If it says centuries or longer, you have a strong password.

Passwords across different types of accounts

Your email password is the most important one you have. If someone cracks your email, they can reset the password on every other account you own — banking, social media, work, shopping. Treat your email password as your highest priority. Make it long, make it random, and do not reuse it anywhere.

Your banking password should also be unique and strong, but many banks have additional security like two-factor authentication or security questions, which add a layer of protection even if the password is compromised. Still, use a strong unique password rather than relying on those extra layers.

For less critical accounts — a forum you visit occasionally, a shopping site you use once a year — the stakes are lower, but the principle is the same: use a unique password so that a breach at that site does not expose your email or banking accounts. A password manager makes this effortless because it generates and stores the passwords for you.

What to do if you forget your password

If you create a password you cannot remember, most websites have a "Forgot Password" link on the login page. Click it, and the site will send a reset link to your email address. Click the link in that email, and you can create a new password. This process usually takes a few minutes.

If you use a password manager and forget your master password, the situation is more serious. The password manager cannot unlock itself, and you cannot recover the master password — it is not stored anywhere. You will have to reset your master password using a recovery code that the password manager gave you when you set it up. If you did not save that recovery code, you may lose access to all your stored passwords. When you set up a password manager, save the recovery code in a safe place — printed on paper, or stored in a separate find location.

Frequently Asked Questions

Do I really need uppercase, lowercase, numbers, and symbols?

Not if your password is very long. A 20-character password of all lowercase letters is stronger than a 10-character password with all four types. That said, using all four types does not hurt, and many websites require it. If a site lets you choose, prioritize length over complexity.

Is it safe to write my password down?

Writing it down on paper and storing the paper in a safe place — like a locked drawer at home — is safer than reusing the same weak password across multiple accounts. A password manager is safer still because it encrypts the passwords. Never write a password on a sticky note on your monitor or in an unencrypted document on your computer.

What if a website limits password length to 8 characters?

That website has poor security practices, but you still have to follow their rules. Use all four character types (uppercase, lowercase, numbers, symbols) to maximize the combinations possible within that limit. Consider whether you really need an account there, or whether you can use a different service with better security.

Can I use the same password for accounts I do not care about?

You can, but it is risky. A breach at a minor site might expose that password, and a criminal will test it on your email and banking accounts. The safest approach is a unique password for everything, which is why a password manager exists. If you refuse to use one, at least keep your email and banking passwords completely separate from everything else.

How often should I change my password?

If your password is strong and unique, you do not need to change it regularly. Change it only if you suspect it has been compromised, or if a website tells you there has been a breach. Forcing frequent password changes actually makes people choose weaker passwords, so most security experts now recommend changing only when necessary.