Guide
How to create a strong password
Six rules that protect you far better than a capital letter and an exclamation mark ever will.
Most accounts aren't broken into by someone cleverly guessing a password. They are broken into because a password was short, followed a common pattern, or had already leaked from another site. The good news: a few habits make you very hard to target.
1. Make it long
Length is the single most important factor. Aim for at least 16 random characters, or a passphrase of five or more random words. Every extra character multiplies the number of possibilities an attacker has to try, so a longer password with simple characters beats a short one full of symbols.
2. Make it random
Humans are bad at randomness, and attackers know our habits. Avoid anything that follows a pattern:
- Names, birthdays, pets, teams, places and years.
- Keyboard walks like
qwerty123or1qaz2wsx. - A word with a capital first letter and a number or symbol at the end, like
Summer2024!. - Swapping letters for symbols, like
P@ssw0rd. Cracking tools try these automatically.
The easiest way to get real randomness is a generator. Use the password generator for passwords a password manager will remember, and the passphrase generator for the few you need to type from memory.
3. Use a different password for every account
When a website is breached, leaked email and password pairs are tried on other popular sites within hours. This is called credential stuffing, and it is the most common way accounts are taken over. If every password is unique, a breach at one site stays at that site.
4. Let a password manager remember them
Unique, random passwords for every account only work if you don't have to remember them. A password manager stores them encrypted, fills them in on the right sites (which also protects you from look-alike phishing sites), and syncs them between your devices. Most browsers and phones include one; dedicated apps add features like secure sharing. Protect it with a strong passphrase of six or seven words.
5. Turn on two-factor authentication
Two-factor authentication (2FA) asks for a second proof, such as a code from an authenticator app or a tap on a security key, when you log in from a new device. Even if your password leaks, an attacker can't get in without it. Turn it on first for your email, because email is how every other password gets reset. Where a site offers passkeys, use them: they can't be guessed or phished at all.
6. Check whether your passwords have leaked
Many password managers and browsers now warn you when a saved password appears in a known breach. You can also look up your email address on Have I Been Pwned. If a password has leaked, change it right away, along with any other accounts where you used the same or a similar one.
Weak and strong, side by side
| Password | Why |
|---|---|
Summer2024! | Weak: a word, a year and a symbol, the most common pattern there is. |
P@ssw0rd123 | Weak: symbol substitutions are tried automatically. |
Kx7#pQ2m | Fair: random, but only 8 characters. Crackable in hours after a breach. |
velvet-canyon-oyster-plaza-rumble | Strong: five random words, and easy to remember. |
m2P!vQ8#zR4t@Lx9kW7d | Very strong: 20 random characters, ideal in a password manager. |
Don't use these examples. They are published on the internet now.
Frequently asked questions
Is P@ssw0rd stronger than password?
Barely. Swapping letters for look-alike symbols is one of the first tricks cracking tools try, so "P@ssw0rd" falls almost as quickly as "password". Real strength comes from length and randomness, not substitutions.
Is it OK to write passwords down?
A notebook kept at home is safer than reusing the same password everywhere, because an online attacker can't reach it. A password manager is better still: it is encrypted, backed up and fills passwords in for you.
What are passkeys?
Passkeys replace passwords with a key stored on your phone or computer, unlocked with your fingerprint, face or device PIN. They can't be guessed, reused or phished. Where a site offers passkeys, they are the most secure option.
How do I know if my password has leaked?
Many password managers and browsers warn you automatically. You can also check your email address on Have I Been Pwned, a free service that tracks known data breaches. If an account shows up, change that password and any others that were similar.