Here’s the dirty secret of password advice: almost nobody follows it — not because people are lazy, but because most of it is unusable. “Use 16 random characters with symbols” is technically correct and practically useless advice if you then have to remember it.
And remembering is the real problem. Password-manager surveys put the average person at somewhere around 80 to 100 online accounts — email, banking, shopping, streaming, work tools, that forum you joined in 2014 and forgot about. Nobody memorizes 100 unique random passwords — so people reuse three or four everywhere and hope for the best.
This guide gives you the two methods that actually work — one for the 95 passwords you should never have to remember, and one for the 5 you must.
Forget complexity rules for a second. Password strength is one thing: how many guesses an attacker needs to try. That number is (size of the character pool) raised to the power of (length) — and length is the exponent, so it does the heavy lifting.
A random 8-character password mixing uppercase, lowercase, numbers, and symbols has about 6.6 quadrillion combinations. Sounds safe — until you learn that a single modern GPU can test billions of guesses per second against a leaked password database. At that speed, 8 characters falls in hours, not years. But add four more characters and the combinations jump past 5 × 1023 — hundreds of thousands of years. Every extra character multiplies the attacker’s work roughly 70 to 95 times.
The honest rule of thumb:
And one thing matters even more than length: uniqueness. A 30-character password reused on 12 sites is worth less than a 12-character password used once. Attackers rarely crack passwords one by one anymore — they take username/password pairs leaked from one breach and spray them across other sites automatically (credential stuffing). Unique-per-site beats long-but-reused, every time.
This is what security professionals actually do: you memorize exactly one password — the master password — and the manager generates, stores, and fills in the other 99.
Some passwords can’t live in a manager — your master password, your laptop login, maybe your email. For those, use a passphrase: several random words strung together.
The math is friendly: from a standard 7,776-word diceware list, each random word adds about 13 bits of strength. Four words lands around 252 (roughly an 8-character random password — fine for everyday logins); five words around 265; six around 277 — effectively uncrackable. For your master password, use five or six random words, and toss in a number or symbol somewhere if you like.
Example of the format (make your own — never use a published one verbatim): trombone-pickle-sunset-42-velvet.
P@ssw0rd1! feels secure and isn’t. Cracking dictionaries contain every leetspeak variant ever invented — swapping letters for symbols adds almost zero real security.At least 12 characters; 16 is the sweet spot for generated passwords you store in a manager. NIST’s digital identity guidelines allow up to 64 characters and stress that length matters more than complexity rules.
Something like k7#Rm2$vQ9xL!wP4z — long, random, mixed characters, unique to one site. But never copy a published example; generate your own with our free password generator.
Yes — reputable ones use zero-knowledge encryption, so even the company can’t read your passwords. The far bigger risk is reusing weak passwords without one. Enable two-factor authentication on the manager itself.
No — NIST dropped mandatory rotation years ago, because forced changes just produce weaker passwords (Password1 → Password2). Change a password immediately if the site reports a breach; otherwise leave a strong one alone.
No. Attackers deliberately target low-security sites to harvest credentials for credential-stuffing attacks, and “unimportant” sites usually hold your email address — the key to resetting your important accounts.
Set the length, pick your character types, get a cryptographically secure password in one click. Nothing leaves your browser — no signup, no tracking.
Open Password Generator →Related tools: QR Code Generator · Meta Tag Generator · Schema Markup Generator