Most passwords people create are weak — not because they’re lazy, but because the standard advice (add a capital letter and a number) doesn’t actually make passwords stronger. Here’s what actually works.
Short Answer: A strong password is long (16+ characters), random, and unique per account. The easiest way to achieve this: use a password manager to generate and store random passwords for every account, and enable two-factor authentication on important accounts. Don’t try to memorize complex passwords.
What Makes a Password Strong?
Password strength comes down to how long it would take a computer to guess it. Three factors matter:
- Length: Every extra character multiplies the difficulty exponentially. A 16-character password is astronomically harder to crack than an 8-character one
- Randomness: Predictable patterns (Password1!, Summer2024) are in attacker dictionaries. True random character strings are not
- Uniqueness: Using the same password across accounts means one breach compromises everything
The Best Method: Use a Password Manager
You don’t need to memorize strong passwords — you need a password manager to generate and store them. This is the single most impactful change you can make to your account security.
Recommended password managers:
- Bitwarden — free, open source, best free option
- 1Password — best paid option, excellent for families
- Google Password Manager — built into Chrome, free, syncs with Android
How to use a password manager for new accounts:
- When signing up for an account, click “generate password” in your password manager
- Use a 20-character random string (letters, numbers, symbols)
- The manager stores it — you never need to type or remember it
- When you return, the manager autofills it for you
If You Must Create a Memorable Password
For the few passwords you must remember (your password manager master password, your device PIN), use a passphrase: four or more random common words strung together.
Example: correct-horse-battery-staple
This is both memorable and extremely difficult to crack — 28 characters with real word entropy. The words must be chosen randomly (not a phrase you’d naturally say), and ideally include a number or symbol.
Warning: Don’t use the same password anywhere. If one service gets breached and your password is exposed, attackers will try that exact password on every other service. Unique passwords per account are non-negotiable.
Password Don’ts
- Don’t use personal info (name, birthday, pet’s name, phone number)
- Don’t use simple substitutions (P@ssw0rd is well-known and in crack dictionaries)
- Don’t use dictionary words alone (even “correct” alone is weak)
- Don’t reuse passwords across sites
- Don’t store passwords in a plain text file or email draft
Enable Two-Factor Authentication (2FA)
Even a strong password can be stolen through phishing or data breaches. 2FA adds a second layer — even if an attacker gets your password, they still need your phone to log in.
Enable 2FA on every account that offers it, especially: email, banking, social media, and cloud storage. Use an authenticator app (Google Authenticator or Authy) rather than SMS-based 2FA where possible — SMS is vulnerable to SIM swapping.
Priority order:
1. Get a password manager → 2. Change top 5 accounts to generated passwords → 3. Enable 2FA on email and banking → 4. Gradually update remaining accounts
FAQ
How long should a password be?
16 characters minimum for general accounts; 20+ characters for financial or email accounts. With a password manager, length doesn’t matter for memorization — make them as long as the site allows.
Is it safe to store passwords in a browser?
Better than nothing, but a dedicated password manager is more secure. Browser passwords are protected by your device’s login but don’t have the zero-knowledge encryption of dedicated managers.
How do I check if my password has been in a data breach?
Go to HaveIBeenPwned.com and enter your email address. It shows which services you’ve used have been breached. If a service you use shows up, change that password immediately.
Quick checklist:
- ✅ Install Bitwarden (free) or 1Password and start using generated passwords
- ✅ Change passwords for email, banking, and social media accounts first
- ✅ Enable 2FA on your email account — it’s your account recovery lifeline
- ✅ Check HaveIBeenPwned.com to see if your email appears in known breaches
Get Bitwarden Free ↗ ↗Check Your Email on HIBP
Conclusion
The goal isn’t to memorize better passwords — it’s to stop memorizing passwords entirely. A password manager with generated unique passwords for every account, combined with 2FA on your most important accounts, protects you against the vast majority of real-world account attacks. Check our guide on internet safety and security for more protection strategies.
