Explainer

How to Create a Strong Password You Can Actually Remember

Length beats complexity. Why a random passphrase is stronger than "P@ssw0rd!", how attackers really crack passwords, and when to let a generator do it for you.

Daniel VAugust 20, 20266 min read

Most advice about passwords is stuck in the past, all forced symbols and quarterly changes. What actually keeps an account safe is simpler and, once you understand why, easier to live with. Here is how attackers really crack passwords, and what to do about it.

Length beats complexity

The strength of a password is roughly how many guesses an attacker would need. Each extra character multiplies that number far more than swapping an a for an @ does. A short password full of symbols like P@ssw0rd! is weak because it is short and follows a predictable pattern that cracking tools expect. A longer string, even of ordinary words, is exponentially harder.

This is why a four-word passphrase such as correct-battery-lamp-otter is stronger than a fiddly eight-character one, and you can actually remember it. Aim for at least 12 characters, and prefer 16 or more for anything important.

How passwords really get cracked

Attackers almost never sit typing guesses at a login box; rate limits stop that. Instead:

  • Credential stuffing: they take username and password pairs leaked from one breached site and try them everywhere else. This is why reuse is the single biggest risk.
  • Offline cracking: if a site's hashed passwords leak, they run billions of guesses per second against the hashes, starting with common passwords, dictionary words, and known patterns.
  • Phishing: they simply trick you into typing it. No password strength helps here, which is why a second factor matters.

The three rules that matter

  1. Long and unpredictable. A random passphrase or a generated string, not a name, date, or keyboard pattern.
  2. Unique per account. So one breach cannot unlock the rest. This is impossible to do by memory across dozens of sites, which is what password managers are for.
  3. Two-factor where it is offered. Even a cracked password is useless without the second factor. Prefer an authenticator app over SMS.

Forget the old rules about changing it every month

NIST, the US standards body whose password guidance most companies eventually follow, dropped the recommendation for forced periodic password changes years ago. Its current guidance (NIST SP 800-63) says a password should only be reset when there is actual evidence it was compromised, not on a calendar. Changing a password on a schedule mostly trains people to pick weaker, more predictable ones (Summer2026!, then Autumn2026!) and does nothing against the credential stuffing and offline cracking described above. The same guidance also recommends checking new passwords against lists of known breached passwords rather than forcing arbitrary symbol rules, which is exactly why length and uniqueness matter more than a forced ! at the end.

When to let a generator do it

For the handful of passwords you must memorise (your device login, your password manager's master password), a passphrase you invent is ideal. For everything else, a random generated password stored in a manager is stronger and you never need to type it. Our password generator builds one using the browser's cryptographically secure random source, entirely on your device, and nothing is sent anywhere. Set the length to 16 or more, include the character types the site requires, and copy it straight into your manager.

The takeaway: stop memorising clever substitutions. Make the few passwords you need long and memorable, generate the rest, and never reuse one.