How to create a strong password?

A strong password is one that an attacker cannot guess in any realistic amount of time — and that you have not used anywhere else. Short and predictable passwords are the ones that get guessed, and a reused password is tried on other services after a leak; both weaknesses are easy to fix. A strong password does not protect against everything: it will not stop a phishing page or malware, which is why the last steps below are not about the password itself. This article gives the short answer first and then explains why each step works.

The short answer

  1. Generate the password instead of inventing it: 16 characters or more, wherever the site allows it.
  2. Use every kind of character the site accepts: upper-case and lower-case letters, digits and symbols.
  3. Save it in a password manager.
  4. Use it for one account only.
  5. Turn on two-factor authentication, or a passkey where the service offers one, and keep the recovery codes.

What makes a password strong

Three properties decide it. Length: every extra random character multiplies the number of combinations an attacker has to try. Randomness: a password is only as strong as the process that produced it, so twelve characters picked by a machine are far stronger than twelve characters that spell a name and a year. Uniqueness: a password used on two sites is only as safe as the weaker site, because passwords leaked from one service are routinely tried on all the others.

Strength is measured in bits of entropy, and each bit doubles the number of guesses needed. A character chosen at random from 62 possibilities — the Latin letters a–z and A–Z and the digits 0–9, all equally likely — adds about 6 bits, so 12 such characters give roughly 71 bits and 16 give roughly 95. These figures hold only when every character is chosen independently and at random; they say nothing about a password a person made up. On the scale our generator shows for the passwords it creates, 60 bits is reasonable for an everyday account, 80 is strong, and 100 is beyond the practical reach of brute force with today's hardware. These are reference points rather than a standard: how much a password withstands in practice also depends on how the service stores it and on how it is attacked.

Why the usual tricks do not work

People choose passwords in remarkably similar ways, and cracking tools are built around those habits:

The common flaw is that they follow predictable patterns of human choice. Rules meant to force complexity — a symbol, a digit, a new password every 90 days — push people towards exactly these patterns. That is why current guidance from NIST tells services not to impose composition rules or scheduled changes, and to check new passwords against lists of leaked ones instead.

A password you have to type yourself: use a passphrase

A few passwords have to be typed without a password manager at hand: the master password of the manager itself, the login of your computer or phone, and for many people the password to the main email account. For these, use a passphrase — several words chosen at random, not a sentence you made up. The classic method is Diceware, and the EFF publishes word lists made for it; use the one called EFF Long Wordlist, in English:

  1. Open the list: it has 7,776 words, each numbered with five digits from 1 to 6.
  2. Roll an ordinary six-sided die five times, or five dice at once and read them from left to right, and write the five digits down in that order.
  3. Find the word with that number.
  4. Repeat until you have six words.
  5. Keep the words exactly as they came out, even if one of them repeats or you would have chosen nicer ones. To remember them, make up a picture or a story around them — without changing the words or their order.

Each word adds about 12.9 bits, so five words give about 65 bits and six about 78, and six ordinary words are far easier to remember and to type than a string of symbols of the same strength. Two conditions make it work. The words must be chosen by chance, because a line from a song or a favourite quotation is already in the attackers' dictionaries; for the same reason, never use a phrase you have seen as an example anywhere. And the phrase must not be reused: one passphrase, one place.

Every other password: generate it

For the dozens of accounts whose passwords you never type by hand, there is no reason to invent anything. Our strong password generator creates each password in your browser with the Web Crypto API, and it is never sent to a server. Set Length to 16 or more, choose the character classes the site accepts, and press Generate; the entropy estimate under the result shows the strength in bits. No look-alikes removes the characters that are easy to confuse (Il1O0o) when a password has to be read aloud or typed from a screen, and Count produces a whole list when you are setting up several accounts at once.

Some sites still cap the length or forbid certain symbols. If one rejects the result, switch off only the kinds of symbols it forbids and keep the length; shorten the password only when the site really limits it. Either way, do not fall back on an invented password: a random password of 12 characters is still far better than a clever one.

Where to keep passwords

A unique random password for every account is easiest to keep in a password manager: it stores them, fills them in, and many managers also warn you when one of them appears in a known breach. You then remember one passphrase instead of a hundred passwords. If you would rather not use a manager, a notebook kept in a safe place at home, out of sight of visitors, is a smaller risk than reusing passwords. What does not work is a text file on the desktop, a note in a messenger, or a sticker on the monitor at work.

A short checklist

To see why these rules exist, read how passwords get cracked. More articles are collected in the password guides.