Most accounts aren't hacked by someone guessing your password by hand. They're broken by software that tries billions of combinations, starting with common passwords, words and patterns, or by reusing passwords leaked from other sites. A strong password defeats both.
What makes a password strong
- Length. Every extra character multiplies the number of possible passwords. Aim for at least 12 characters, and 16 or more for important accounts.
- Randomness. “Summer2026!” looks complex but follows a pattern attackers try early. Truly random choices have no pattern to exploit.
- Uniqueness. A password used on two sites is only as safe as the weaker site.
Passphrases: strong and memorable
A passphrase is a few random words strung together, like otter-lunar-stump-fiber-quiet. Five or six
truly random words are very hard to crack, yet much easier to remember and type than gE*bBfda8vuTX_jU.
The key is that the words must be chosen randomly, not picked by you, which is what the
password generator's passphrase mode does.
How strong is strong enough?
Strength is measured in bits of entropy. Each extra bit doubles the number of guesses needed.
| Password type | Entropy |
|---|---|
| 8 random lowercase letters | About 38 bits (weak) |
| 5 random words | About 52 bits (fair) |
| 7 random words | About 72 bits (strong) |
| 16 random mixed characters | About 100 bits (very strong) |
Habits that matter more than any single password
- Use a password manager. It creates and remembers a unique password for every site, so you only need one strong passphrase.
- Turn on two-factor authentication for email, banking and social media. Even a stolen password isn't enough then.
- Protect your email account most of all. It can reset the passwords of everything else.
- Change passwords after a breach, starting with any site where you reused the leaked one.