How to create a strong password you can actually remember

What makes a password hard to crack, why passphrases work so well, and simple habits that keep your accounts safe.

5 min read

Most accounts aren't hacked by someone guessing your password by hand. They're broken by software that tries billions of combinations, starting with common passwords, words and patterns, or by reusing passwords leaked from other sites. A strong password defeats both.

What makes a password strong

  • Length. Every extra character multiplies the number of possible passwords. Aim for at least 12 characters, and 16 or more for important accounts.
  • Randomness. “Summer2026!” looks complex but follows a pattern attackers try early. Truly random choices have no pattern to exploit.
  • Uniqueness. A password used on two sites is only as safe as the weaker site.

Passphrases: strong and memorable

A passphrase is a few random words strung together, like otter-lunar-stump-fiber-quiet. Five or six truly random words are very hard to crack, yet much easier to remember and type than gE*bBfda8vuTX_jU. The key is that the words must be chosen randomly, not picked by you, which is what the password generator's passphrase mode does.

How strong is strong enough?

Strength is measured in bits of entropy. Each extra bit doubles the number of guesses needed.

Password typeEntropy
8 random lowercase lettersAbout 38 bits (weak)
5 random wordsAbout 52 bits (fair)
7 random wordsAbout 72 bits (strong)
16 random mixed charactersAbout 100 bits (very strong)

Habits that matter more than any single password

  1. Use a password manager. It creates and remembers a unique password for every site, so you only need one strong passphrase.
  2. Turn on two-factor authentication for email, banking and social media. Even a stolen password isn't enough then.
  3. Protect your email account most of all. It can reset the passwords of everything else.
  4. Change passwords after a breach, starting with any site where you reused the leaked one.