How to Create a Strong Password
- Updated
- 5 min read
Short answer
A strong password is long, random and used for only one account. Aim for at least 12 to 16 random characters, or a passphrase of five or more randomly chosen words, and store it in a password manager. Length adds more strength than swapping letters for symbols.
Most accounts are not broken by someone cleverly guessing a password. They are compromised when a password is reused after a data breach, is predictable enough to appear in the lists attackers try first, or is handed over on a fake login page. A strong password handles the first two problems; good habits such as multi-factor authentication handle the rest.
Step by step
- 1Use a password manager or a trusted generator to create the password, rather than inventing one yourself. People are poor at being random.
- 2Make it long: 16 or more characters for a generated password, or five to six words for a passphrase.
- 3Include a mix of character types if the site allows, but prioritize length over complexity.
- 4Use a different password for every account, so a breach at one site does not unlock the others.
- 5Turn on multi-factor authentication, especially for email, banking and your password manager.
- 6Change a password promptly if the service reports a breach or you suspect it has been exposed; routine forced changes are not otherwise necessary.
Formulas
Entropy (bits) = L × log₂(N)- L
- length, the number of characters or words
- N
- the size of the pool each character or word is drawn from
This only applies when every character or word is chosen at random. A human-chosen password has far less real entropy than the formula suggests.
Combinations = N^L = 2^entropyEach extra bit of entropy doubles the number of guesses an attacker would need to try every option.
Skip the arithmetic
Generate strong random passwords in your browser with the options you choose.
Worked examples
8 random characters from all 94 printable keyboard symbols
- 1log₂(94) ≈ 6.55 bits per character
- 28 × 6.55 ≈ 52.4 bits
- 394^8 ≈ 6.1 quadrillion combinations
About 52 bits. As a rough illustration only, a well-equipped attacker making 10 billion guesses a second against a fast, unsalted hash could try every combination in about a week.
16 random lowercase letters vs 8 characters from the full set
- 1log₂(26) ≈ 4.70 bits per letter
- 216 × 4.70 ≈ 75.2 bits
About 75 bits, far stronger than the 52-bit mixed password, even though it uses only lowercase letters. Doubling the length beat quadrupling the pool.
A passphrase of random words from a 7,776-word list
- 1log₂(7,776) ≈ 12.9 bits per word
- 25 words: 5 × 12.9 ≈ 64.6 bits
- 36 words: 6 × 12.9 ≈ 77.5 bits
Six random words give roughly the same entropy as 16 random lowercase letters and are much easier to type and remember.
Why does length matter more than complexity?
Every character you add multiplies the number of possible passwords by the size of the pool. Adding symbols to the pool increases N, but only modestly: going from 26 lowercase letters to all 94 printable characters raises the bits per character from about 4.7 to about 6.6. For an 8-character password, that switch adds roughly 15 bits, while simply adding four more lowercase letters adds about 19, and length keeps paying off with every character.
Complexity rules also backfire in practice. Asked to include a capital, a number and a symbol, most people produce something like Summer2024!, which follows such a common pattern that it offers little real protection. Length combined with genuine randomness is what makes a password hard to guess.
What does entropy actually tell you?
Entropy measures how many guesses an attacker would need if they knew exactly how your password was generated but not the result. It is a property of the method, not of the finished string. A random generator producing 16 characters has about 105 bits of entropy. A password you chose from your pet's name and birth year might look just as complicated to a strength meter but may fall in the first few million guesses.
Real crack times depend on factors outside your control: how the site stores passwords, whether it uses a slow hashing algorithm, and how much computing power an attacker has. The time estimates in this guide are illustrations of scale, not predictions.
Are passphrases better than passwords?
They can be, if the words are picked randomly. A passphrase such as five or six words drawn by dice or a generator from a long word list is strong and memorable, which makes it a good choice for the few passwords you have to type yourself, such as your computer login or password manager.
A phrase you make up, like a song lyric or a quote, is not random. Attackers include common phrases and quotations in their guess lists.
Habits that protect you more than any single password
- Never reuse passwords. Credential stuffing, where attackers try leaked email and password pairs on other sites, is one of the most common ways accounts are taken over.
- Use a password manager so every account can have a long random password without you remembering any of them.
- Enable multi-factor authentication. An authenticator app or security key is stronger than text-message codes, but any second factor is better than none.
- Protect your email account most carefully, since it can reset almost every other password.
- Type addresses yourself or use bookmarks instead of logging in through links in emails; a strong password does not help if you enter it on a fake site.
Common mistakes
- Predictable substitutions such as P@ssw0rd, which attackers try automatically.
- Keyboard patterns like qwerty123 or 1q2w3e4r.
- Personal details: names, birthdays, pets, teams or addresses.
- Adding a number to the end of an old password when forced to change it.
- Trusting a strength meter that only checks for character types.
Frequently asked questions
How long should a password be?
For generated passwords stored in a manager, 16 characters or more is a comfortable choice. For a password you must remember, a random passphrase of five or six words is a practical alternative.
Are password managers safe?
A reputable password manager, protected by a strong master passphrase and multi-factor authentication, is generally far safer than reusing or writing down passwords. It concentrates your risk, so that master passphrase must be unique and strong.
Should I change my passwords regularly?
Current guidance from security bodies such as NIST advises against forced periodic changes, because they encourage predictable patterns. Change a password when there is a reason, such as a breach.
Is it safe to use an online password generator?
It is safest when the password is generated locally in your browser with a cryptographically secure random source and never sent over the network. Toolvix's password generator works that way.
What makes a password weak even if it is long?
Predictability. A long password built from a famous phrase, repeated words or personal details can be guessed much faster than its length suggests, because it was not chosen at random.