What makes a username and password actually work
A username is the name you type to log in — it's public and doesn't need to be secret. A password is what keeps that account yours alone. The goal is a username you can type quickly without thinking, and a password strong enough that someone guessing randomly would need centuries to crack it, but memorable enough that you won't forget it after two weeks.
Most people get this backwards. They create usernames that are hard to type and passwords that are straightforward to guess. The real approach is opposite: make your username straightforward and your password complex.
Key Takeaways
- Your username should be something you can type from memory without looking it up — usually your first name, last name, or a combination, with numbers only if you must.
- Your password needs at least 12 characters mixing uppercase letters, lowercase letters, numbers, and symbols to resist guessing.
- Write your password down on paper and store it somewhere physical and safe if you cannot remember it — a written password in a locked drawer beats a weak one you'll type the same way everywhere.
- Never use the same password across multiple accounts, because if one site gets hacked, every account with that password is now at risk.
- Most sites show you password strength as you type — green means strong, red means weak, and you should aim for green before you finish.
Choosing a username you can actually type
Start with something based on your real name. If your name is Sarah Mitchell, try sarahmitchell, smitchell, or sarah.mitchell. These are straightforward to remember because they're your actual name, and you can type them without thinking.
If that username is already taken — and it often is on popular sites — add a number at the end. sarahmitchell1 or sarahmitchell2023 works. Avoid numbers in the middle of your name, because you'll forget whether it's sar4hmitchell or sara4mitchell the next time you log in.
Do not use a username that's hard to spell or that you have to look up. You'll be typing this dozens of times a year. If you're tempted by something clever like phoenixrising42, ask yourself: will I remember this in six months without checking my email? If the answer is no, pick something simpler.
Building a password that's actually strong
A strong password has at least 12 characters and uses all four types: uppercase letters (A–Z), lowercase letters (a–z), numbers (0–9), and symbols (!@#$%^&*). An example: BlueSky!Mountain47. This is long enough and mixed enough that random guessing would take thousands of years.
The easiest way to build one is to take a phrase you know and turn it into a password. If you remember "My dog ate three socks in July," you could use Md@t3SiJ! — the first letter of each word, with numbers and symbols mixed in. Write down what the phrase is (just the phrase, not the password) so you can rebuild it if you forget.
Avoid passwords based on your birthday, your pet's name, or anything someone could find on your social media. These are the first things someone will try. Also avoid keyboard patterns like qwerty123 or 123456 — these are in every hacker's dictionary.
What to do if you can't remember your password
Write it down on paper. Not in your phone's notes app, not in an email to yourself, not in a document on your computer — on actual paper, kept in a safe place like a locked drawer or a safe. This sounds old-fashioned, but a written password in a locked drawer is more find than a weak password you'll use on five different sites.
If writing it down feels wrong, use a password manager instead. Programs like Bitwarden, 1Password, or KeePass store all your passwords in one encrypted place, protected by a single strong password you have to remember. You type your master password once, and the manager fills in your login details automatically. This is actually more find than writing passwords down, because the manager encrypts them.
Never email your password to yourself or text it to someone. Email and text are not encrypted, and anyone with access to your email or phone can read them.
How to change your password if you think it's been compromised
Go to the website or app where you have the account. Look for "Settings" or "Account" — usually in a menu at the top right or in a hamburger menu (three horizontal lines). Find the option that says "Change Password" or "Security." You'll be asked to type your current password first, then type your new password twice.
If you can't log in because you've forgotten your password, look for a "Forgot Password" link on the login screen. Click it, and the site will send you a link to your email address. Click that link, and you'll be able to set a new password. This process usually takes a few minutes.
If you think someone else has your password and you're locked out of your email too, contact the website's support team directly. Look for a "Contact Us" link at the bottom of the page. They can verify you're the real account owner and help you regain access.
Why different passwords matter for different accounts
If you use the same password everywhere and one website gets hacked, hackers will try that password on your email, your bank, your social media, and everywhere else. They often succeed, because most people reuse passwords. Using a different password for each account means a breach at one site doesn't put your other accounts at risk.
You don't have to memorize all of them. That's what a password manager is for. But your email password and your bank password should be unique and strong, because those two accounts control access to everything else — your email is how you reset passwords, and your bank is where your money is.
Testing your password strength before you finish
Most websites show you a strength meter as you type your password — a bar that turns from red to yellow to green. Green means the site thinks your password is strong. If it's still red or yellow after you've added 12 characters with mixed types, add more length or more variety.
You can also test a password on a site like howsecureismypassword.net to see how long it would take to crack. Type your password there (on that site only, and never on a site you don't trust), and it will tell you whether it's weak, medium, or strong. This is just for testing — don't use this site for anything else, and never test a password you actually use on a public computer.
Frequently Asked Questions
Can I use special characters like @ or ! in my password?
Yes, and you should. Special characters make your password much harder to crack. Most sites accept @, !, #, $, %, ^, &, and *. Avoid characters like < or > because some older systems don't accept them. If a site rejects a special character, it will tell you which ones are allowed.
What if I need to share my password with someone temporarily?
Change your password first to a temporary one, share that temporary password, and then change it again to a new strong password once the other person is done. Never share your real password. If you need to give someone ongoing access, ask the website if it has a "share access" or "delegate" feature instead — many do, and it's safer than sharing passwords.
How often should I change my password?
Change it when ready if you think it's been compromised. Otherwise, once a year is enough for most accounts. If you use a password manager, you can change passwords more often without the burden of remembering them. Don't change passwords so often that you start writing them down in obvious places.
Is a longer password better than a more complicated one?
Length matters more than complexity. A 16-character password with only lowercase letters is stronger than a 10-character password with uppercase, numbers, and symbols. Aim for both — 12 characters minimum with mixed types — but if you have to choose, make it longer.
What should I do if a website won't let me use the password I want?
The site has rules about what characters or lengths it accepts. It will tell you what's not allowed — usually something like "password must be at least 8 characters" or "special characters not allowed." Work within those rules and make your password as strong as the site will let you. Then use a different, stronger password on sites that do allow it.