Weak and reused passwords are behind the majority of hacked accounts. Yet most advice about passwords is either vague ("make it complex!") or impossible to follow (a different 16-character jumble for all fifty of your accounts). The truth is more practical — and more reassuring: a genuinely strong password is mostly about length, and you can create one that's both hard to crack and easy to remember.
This guide explains what actually makes a password strong, shows you a simple method to build one, and covers the mistakes that quietly put your accounts at risk.
Key takeaways
- Length beats complexity — a long password is far harder to crack than a short, symbol-heavy one.
- A "passphrase" of a few random words is both strong and memorable.
- Never reuse the same password across accounts; one leak then unlocks the rest.
- Use a password manager so you can have long, unique passwords everywhere without memorising them all.
What actually makes a password strong?
A password's strength comes down to how many guesses an attacker would need to crack it. Two things drive that number: how long the password is, and how unpredictable each character is. Of the two, length matters most. Every extra character multiplies the possible combinations, so a longer password becomes exponentially harder to break.
This is why a short password full of symbols — say eight characters like a typical "strong" password a website forces on you — is actually weaker than a longer, simpler one. Modern computers can try billions of short combinations per second. A 16-character password, even without exotic symbols, pushes the time to crack it into the realm of centuries.
Length beats complexity
Security researchers largely agree: aim for length first. A password of 16 characters or more is a strong target for anything that matters, and longer is better for your most important accounts (email, banking, your password manager). Mixing in uppercase, numbers and symbols still helps, but it's the icing — the length is the cake. A memorable 20-character phrase will out-protect a cryptic 8-character code every time.
The passphrase method (strong and memorable)
The easiest way to get length without a headache is a passphrase: a string of a few random, unrelated words. Picture four random words like "copper-otter-violin-cloud". That's 24 characters, easy to visualise, and extremely hard to guess — because the strength comes from the randomness of the word choice, not from obscure symbols.
To build a good passphrase:
- Choose four or more random words that have no obvious connection to each other or to you.
- Join them with hyphens, spaces or a symbol to add length and separation.
- Sprinkle in a capital letter and a number or two if the site requires them.
- Avoid famous phrases, song lyrics or quotes — attackers feed those into their tools.
The result is a password you can actually picture in your mind, yet one that would take an attacker an impractically long time to crack.
Common password mistakes to avoid
- Reusing passwords. The single biggest risk. When one site is breached, attackers try that same email and password on every other popular service — a technique called credential stuffing. One unique password per account stops this cold.
- Using personal information. Names, birthdays, your pet, your favourite team — all easily found on social media and tried first.
- Predictable substitutions. Swapping "a" for "@" or "o" for "0" in a common word (like "P@ssw0rd") fools no one; cracking tools expect it.
- Sequences and keyboard patterns. "123456", "qwerty" and "abcabc" are among the first things guessed.
- Too short. Anything under about 12 characters is increasingly vulnerable, no matter how clever it looks.
Should you use a password generator?
For accounts you don't need to type often, the strongest option is a truly random password from a generator — a long string of random letters, numbers and symbols. You don't have to remember it if you store it in a password manager. A good generator uses your browser's cryptographically secure randomness, so the result is genuinely unpredictable, and a strength meter shows you how tough it is. Generate a long, unique password for each account and let the manager do the remembering.
How a password manager ties it together
You can't memorise a unique 16-character password for every account — nobody can, and you shouldn't try. A reputable password manager stores them all behind one strong master password (make that one a memorable passphrase), fills them in automatically, and even flags reused or breached passwords. It turns "strong, unique passwords everywhere" from an impossible chore into a one-time setup. Pair it with two-factor authentication (2FA) on your important accounts, and even a stolen password usually isn't enough for an attacker to get in.
Conclusion
Creating a strong password isn't about torturing yourself with unmemorable symbols. Make it long, make it unique to each account, and either use a memorable passphrase or a random generated password stored in a manager. Do that, add 2FA where it counts, and you've closed the door on the vast majority of account hacks. Ready to create one now? Try the free Password Generator to produce a strong, random password in seconds — generated privately in your browser and never uploaded.
Frequently asked questions
What makes a password strong?
Mainly its length and unpredictability. A long password (16+ characters) is far harder to crack than a short one, even a short one full of symbols. Uniqueness matters too — the password should not be reused anywhere else.
How long should a strong password be?
Aim for at least 16 characters, and longer for critical accounts like email, banking and your password manager. Every extra character makes the password exponentially harder to crack.
What is an example of a strong password?
A random passphrase such as four unrelated words joined together — for example a combination like "copper-otter-violin-cloud" with a capital and a number added — is both strong and memorable. A random string from a generator is even stronger if you store it in a password manager.
Is it safe to use a password generator?
Yes, if it runs in your browser using secure randomness and never uploads the result. The password is created locally on your device, so it isn't transmitted or stored anywhere. Save it in a password manager so you don't have to remember it.
Should I use a different password for every account?
Absolutely. Reusing a password means one data breach can unlock all your accounts. A unique password per account — managed with a password manager — is one of the most effective security habits you can adopt.
Try the tool
Create strong, random, secure passwords with custom length and character options (uppercase, numbers, symbols). Includes a live strength meter — generated locally so your password never leaves your device.
🔐 Open Password Generator