Most accounts aren’t hacked by someone cleverly guessing a password. They’re broken into because the password was reused and leaked from another site, was phished, or was short enough to crack once a database was stolen. So a strong password strategy has three parts: make each password long and random, never reuse one, and add a second factor so a stolen password alone isn’t enough.
Length beats complexity
Password strength is about how many guesses an attacker needs. That number grows much faster with length than with character variety:
| Password type | Example pattern | Approx. strength |
|---|---|---|
| 8 lowercase letters | tvqmxrae |
~38 bits |
| 8 random characters from all 94 printable ASCII | k#9Lq!2v |
~52 bits |
| 4 random words (from a 7,776-word list) | orbit-cactus-velvet-lamp |
~52 bits |
| 6 random words | orbit-cactus-velvet-lamp-fjord-mint |
~78 bits |
| 16 random characters from all 94 | t7&Qm2!vR9#pLx4z |
~105 bits |
Each extra bit doubles the number of guesses. These figures assume the password is truly random. Human-chosen passwords like Summer2026! look complex but appear in every cracking dictionary, so their real strength is tiny.
Current guidance reflects this. NIST’s Digital Identity Guidelines (SP 800-63B, revision 4, finalised in 2025) say:
- passwords used as the only factor should be at least 15 characters,
- sites should allow at least 64 characters and accept spaces and all characters,
- sites should not force composition rules (one uppercase, one symbol…),
- sites should not force periodic changes, only changes after a suspected compromise,
- sites should check new passwords against lists of breached and common passwords.
Passphrases: strong and memorable
For the few passwords you have to type or remember (your computer login, your password manager’s master password), use a passphrase of random words:
copper-ladder-quietly-mango-harbour
The words must be picked randomly, by dice or a generator, not chosen by you, and not a song lyric or famous quote. Five or six words is plenty for a master password. Our password generator can create random passwords or passphrases locally in your browser.
Use a password manager for everything else
Nobody can remember 100 unique 16-character passwords, and you shouldn’t try. A password manager (Bitwarden, 1Password, Proton Pass, or the built-in managers in Apple, Google and Microsoft ecosystems):
- generates a unique random password for every site,
- fills it in automatically, and only on the correct domain, which also helps against phishing,
- syncs across devices, encrypted with a key only you hold,
- warns you about reused, weak or breached passwords.
Protect the manager itself with a strong passphrase and two-factor authentication, and store recovery codes somewhere safe offline.
Two-factor authentication and passkeys
A second factor means a stolen password isn’t enough on its own. From weakest to strongest:
- SMS codes: better than nothing, but vulnerable to SIM-swap fraud.
- Authenticator app codes (TOTP): Google Authenticator, Microsoft Authenticator, Authy, or your password manager.
- Push approvals: convenient, but beware “approve” fatigue attacks; never approve a login you didn’t start.
- Security keys and passkeys: phishing-resistant, because the browser checks the real domain cryptographically.
Turn on 2FA first for your email account: whoever controls your inbox can reset almost every other password. Then banking, your password manager, cloud storage and social media. Where a site offers passkeys, they’re the most convenient and secure option available today.
How websites store your password (hashing)
A well-run site never stores your actual password. It stores a hash: a one-way fingerprint produced by a function designed so you can’t reverse it. When you log in, the site hashes what you typed and compares the results.
- Fast hashes like MD5 or SHA-256 are fine for checksums but bad for passwords: modern GPUs can try billions of them per second. You can see how they work with our hash generator.
- Password hashing functions such as Argon2id, bcrypt or scrypt are deliberately slow and memory-hungry, so each guess costs the attacker real time.
- A random salt per user means two people with the same password get different hashes, so attackers can’t crack everyone at once.
That’s why length matters: if a site’s database is stolen, a long random password stays uncracked even when a short one falls within hours. And it’s why reuse is so dangerous: one badly run site leaks the password you also use for your email.
What to do after a data breach
If a service you use reports a breach, or a breach-alert service flags your email address:
- Change the password for that service immediately, using a new random one.
- Change it anywhere you reused it. This is where reuse really hurts.
- Turn on 2FA if it wasn’t already.
- Watch for phishing. Attackers use leaked names and email addresses to send convincing follow-up messages “from” the breached company.
- Check account activity such as login history, forwarding rules in email, and saved payment methods.
If financial details were exposed, contact your bank or card provider directly using the number on your card, not a number from an email.
Common mistakes
- Reusing a “strong” password across sites.
- Predictable patterns:
Password1!, a pet’s name plus a year, keyboard walks likeqwerty123. - Small variations of an old password (
Spring2026!→Summer2026!). - Storing passwords in a plain notes app or spreadsheet.
- Answering security questions truthfully. Treat them as extra passwords and store random answers in your manager.
Checklist
- A password manager with a strong, unique passphrase as the master password.
- Every account has its own random password, 16+ characters where allowed.
- 2FA on email, banking, password manager and social accounts; passkeys where offered.
- Breach alerts enabled (many managers check against known breach databases).
- Recovery codes printed or stored safely offline.