How to Create a Strong Password (And Actually Remember It)

A k 7 # % 5 & * ? +

Here’s the dirty secret of password advice: almost nobody follows it — not because people are lazy, but because most of it is unusable. “Use 16 random characters with symbols” is technically correct and practically useless advice if you then have to remember it.

And remembering is the real problem. Password-manager surveys put the average person at somewhere around 80 to 100 online accounts — email, banking, shopping, streaming, work tools, that forum you joined in 2014 and forgot about. Nobody memorizes 100 unique random passwords — so people reuse three or four everywhere and hope for the best.

This guide gives you the two methods that actually work — one for the 95 passwords you should never have to remember, and one for the 5 you must.

What actually makes a password strong (it’s mostly length)

Forget complexity rules for a second. Password strength is one thing: how many guesses an attacker needs to try. That number is (size of the character pool) raised to the power of (length) — and length is the exponent, so it does the heavy lifting.

A random 8-character password mixing uppercase, lowercase, numbers, and symbols has about 6.6 quadrillion combinations. Sounds safe — until you learn that a single modern GPU can test billions of guesses per second against a leaked password database. At that speed, 8 characters falls in hours, not years. But add four more characters and the combinations jump past 5 × 1023 — hundreds of thousands of years. Every extra character multiplies the attacker’s work roughly 70 to 95 times.

The honest rule of thumb:

  • 8 characters — the bare minimum. A floor, not a goal.
  • 12–16 characters — the sweet spot. A random 16-character password would take centuries to brute-force.
  • Character variety helps, but it’s the side dish. A 16-character all-lowercase random password is far stronger than an 8-character mixed one.

And one thing matters even more than length: uniqueness. A 30-character password reused on 12 sites is worth less than a 12-character password used once. Attackers rarely crack passwords one by one anymore — they take username/password pairs leaked from one breach and spray them across other sites automatically (credential stuffing). Unique-per-site beats long-but-reused, every time.

Method 1: Random passwords + a password manager (the gold standard)

This is what security professionals actually do: you memorize exactly one password — the master password — and the manager generates, stores, and fills in the other 99.

  • Every site gets its own unique 16–20 character random string.
  • You never type them — the manager only fills them on the real domain, which blunts phishing.
  • Good managers warn you when one of your sites appears in a breach.
Honest caveats: your master password has to be excellent — use a passphrase (Method 2 below). And you’re trusting one company, so pick a reputable one with zero-knowledge encryption (even the company can’t read your passwords). Bitwarden is free and open source; 1Password and the built-in managers in Apple/Google accounts are solid too. Turn on two-factor authentication on the manager itself.

Method 2: The passphrase (for the few passwords you must memorize)

Some passwords can’t live in a manager — your master password, your laptop login, maybe your email. For those, use a passphrase: several random words strung together.

The math is friendly: from a standard 7,776-word diceware list, each random word adds about 13 bits of strength. Four words lands around 252 (roughly an 8-character random password — fine for everyday logins); five words around 265; six around 277 — effectively uncrackable. For your master password, use five or six random words, and toss in a number or symbol somewhere if you like.

Example of the format (make your own — never use a published one verbatim): trombone-pickle-sunset-42-velvet.

The critical rule: the words must be random. Humans choosing “clever” words pick predictable ones — lyrics, quotes, pet names — and attackers keep dictionaries of all of them. Roll dice or use a generator; don’t hand-pick.

How to create a strong password online (step by step)

1 Set the length to 16 (or higher).
Length beats complexity. Drag the slider on our free password generator to 16 — that’s the default, and it’s the sweet spot.
2 Tick all four character types.
Uppercase, lowercase, numbers, and symbols. More variety per position means more combinations per character.
3 Click Generate.
Passwords are created with your browser’s cryptographically secure random generator — nothing is sent to any server, so nobody (not even us) ever sees them.
4 Check the strength meter.
Aim for “Strong” or “Very Strong” before you copy it.
5 Copy it and save it in your password manager.
Never reuse it on another site. One password, one site — that’s the whole game.

5 mistakes people keep making

  • Reusing one password everywhere. One breach becomes every account — email, banking, shopping. This single habit causes more damage than every other mistake combined.
  • “Clever” substitutions. P@ssw0rd1! feels secure and isn’t. Cracking dictionaries contain every leetspeak variant ever invented — swapping letters for symbols adds almost zero real security.
  • Personal details. Birthdays, pet names, anniversaries, your kid’s school — all visible on your social media, all guessable.
  • Storing passwords in a notes app or spreadsheet. Unencrypted, synced to the cloud, searchable by anyone who picks up your unlocked phone.
  • Skipping two-factor authentication. A password alone is half a lock. Turn on 2FA everywhere it matters — especially your email, since email is the key that resets everything else.

Frequently asked questions

How long should my password be?

At least 12 characters; 16 is the sweet spot for generated passwords you store in a manager. NIST’s digital identity guidelines allow up to 64 characters and stress that length matters more than complexity rules.

What does a strong password look like?

Something like k7#Rm2$vQ9xL!wP4z — long, random, mixed characters, unique to one site. But never copy a published example; generate your own with our free password generator.

Are password managers safe?

Yes — reputable ones use zero-knowledge encryption, so even the company can’t read your passwords. The far bigger risk is reusing weak passwords without one. Enable two-factor authentication on the manager itself.

Should I change my passwords regularly?

No — NIST dropped mandatory rotation years ago, because forced changes just produce weaker passwords (Password1 → Password2). Change a password immediately if the site reports a breach; otherwise leave a strong one alone.

Can I reuse a password on “unimportant” sites?

No. Attackers deliberately target low-security sites to harvest credentials for credential-stuffing attacks, and “unimportant” sites usually hold your email address — the key to resetting your important accounts.

Generate a strong password now — free

Set the length, pick your character types, get a cryptographically secure password in one click. Nothing leaves your browser — no signup, no tracking.

Open Password Generator →

Related tools: QR Code Generator · Meta Tag Generator · Schema Markup Generator