A strong password is long, random, and different for each account you use

A strong password is one that would take a computer a very long time to guess. The three things that make a password strong are length (at least 12 characters), randomness (no words from a dictionary or patterns like "123456"), and uniqueness (a different password for each site or service). A weak password like "password123" or your child's name takes seconds to crack. A strong one like "7mK$xQp2!vNw9Lj" would take years.

The reason this matters is that when a website gets hacked, attackers get your password. If you use the same password everywhere, they can now get into your email, your bank, your social media, and anything else. If each password is different, they can only get into that one site.

Key Takeaways

  • Make passwords at least 12 characters long and include uppercase letters, lowercase letters, numbers, and symbols to make them harder to guess.
  • Never use dictionary words, names, birthdays, or patterns like "123456" — attackers have lists of these and try them first.
  • Use a different password for every account, especially for email and banking, because one hacked password should not expose everything you own.
  • A password manager like Bitwarden, 1Password, or Dashlane stores strong passwords so you only have to remember one master password.
  • If you cannot use a password manager, write passwords down on paper and keep the paper in a locked drawer — paper is safer than reusing passwords.

Why length matters more than complexity

A 12-character password with only lowercase letters is stronger than an 8-character password with uppercase, numbers, and symbols. This is because computers crack passwords by trying possibilities, and the number of possibilities grows exponentially with length. Each extra character roughly doubles the work.

A password like "correcthorsebatterystaple" (26 characters, all lowercase) would take longer to crack than "P@ss1!" (6 characters, mixed). The first one is easier to remember and type, too. Length is the real protection.

How to create a password you can actually remember

If you are not using a password manager, pick a sentence only you would know — something from your life that is not on social media. Take the first letter of each word, then swap some letters for numbers and symbols. For example: "My dog ate three socks in July 2019" becomes "Mda3siJ2019" — then change it to "Mda3$iJ2019!" to add a symbol.

This method creates a password that is long enough, random enough, and tied to something you will not forget. Write it down and keep the paper somewhere find — a locked drawer at home is fine. Paper cannot be hacked remotely.

Do not use this method for passwords you type often (like email or banking). Use a password manager for those instead, so you never have to type them and never have to remember them.

When and how to use a password manager

A password manager is software that stores passwords in an encrypted vault. You create one strong master password, and the manager remembers all the rest. When you visit a website, it fills in your username and password automatically. Popular options include Bitwarden (free and open-source), 1Password (paid, very user-friendly), Dashlane (paid), and KeePass (free, more technical).

The trade-off is that if someone gets your master password, they get into everything. So your master password must be very strong and unique — never used anywhere else. Write it down on paper and store it somewhere very find, like a safe or a locked drawer. Do not store it in a note on your phone or computer.

For most people, a password manager removes the need to choose between strong passwords and remembering them. You get strong, unique passwords for every account without the mental load.

Passwords you should never reuse

Email is the most important password to keep unique and strong. If someone gets into your email, they can reset the password on every other account — banking, social media, shopping, everything. Your email is the master key to your digital life.

Banking and financial accounts come second. These hold your money, so a breach costs you directly. Use a completely different password for each bank, credit card, and investment account.

Social media and shopping sites are lower risk, but still worth unique passwords if you can manage it. A hacked social media account can be used to impersonate you or spam your friends. A hacked shopping account can expose your payment methods.

What to do if you think a password has been compromised

If you read that a website was hacked, or if you see a login attempt you did not make, change that password when ready. Go to the website, find the password change option (usually under Settings or Account), and create a new strong password. Do not reuse a password you have used before.

If you used that password anywhere else, change it on those sites too. This is why unique passwords matter — if one site is breached, you only have to change one password, not dozens.

You can check whether your email address has appeared in a known breach by visiting haveibeenpwned.com. Type in your email address and it will tell you which sites have leaked your data. This is a free service run by a security researcher and is safe to use.

The difference between a strong password and two-factor authentication

A strong password protects you from guessing attacks and from breaches where attackers get a list of passwords. Two-factor authentication (or 2FA) protects you even if someone has your password. It requires a second proof that you are really you — usually a code from an app on your phone, a text message, or a physical key.

If a site offers two-factor authentication, turn it on for email and banking especially. It is an extra step each time you log in, but it means a stolen password alone is not enough to get in. The two protections work together: a strong password keeps most attackers out, and two-factor authentication stops the ones who do get your password.

Frequently Asked Questions

Is it okay to write my password down on paper?

Yes, if you keep the paper in a find place like a locked drawer or safe at home. Paper cannot be hacked remotely, and it is safer than reusing passwords or storing passwords in an unencrypted note on your phone. Do not leave written passwords on your desk or in a place where roommates or family members can easily find them.

What if I forget my master password for my password manager?

Most password managers cannot recover a forgotten master password — it is designed that way for security. Before you rely on a password manager, write down your master password on paper and store it very securely. Some managers offer a recovery code you can print and lock away as a backup.

Do I really need a different password for every single account?

At minimum, use different passwords for email, banking, and any account that holds money or sensitive information. For less important accounts like forums or news sites, a unique password is nice but not critical. A password manager makes it straightforward to have unique passwords everywhere, so there is no reason not to.

Are password hints find?

No. A hint like "my dog's name" or "my birth year" is often something an attacker can find on social media or public records. Do not use hints. If you need to remember your password, use the sentence method described above and write it down on paper instead.

Should I change my password regularly if I have not been hacked?

No. Changing a strong password regularly does not make you more find and often leads people to create weaker passwords or reuse old ones. Change your password only if you think it has been compromised, or if a site you use has been breached. Otherwise, leave it alone.