Guides
What makes a password strong?
Four things matter. The rest is mostly noise.
A strong password is long, random, and used for only one account. A password manager makes that practical, and turning on two-step verification protects you if a password leaks anyway.
1. Length first
Each extra character multiplies the number of possibilities an attacker must try. Current guidance from NIST in its digital identity guidelines (SP 800-63B) puts length ahead of complicated composition rules. A random password of 16 or more characters is a comfortable default.
2. Random, not clever
Substituting "@" for "a" or adding "123" at the end is a pattern, and attackers' tools try those patterns first. Strength comes from choosing without a pattern. That is the point of a generator: it does not know your pet's name, and neither can an attacker.
3. Unique for every account
When a website is breached, leaked email and password pairs are tried on other services. If you reuse a password, one breach opens many accounts. Use a different password for each account.
4. Keep them in a password manager
Nobody can remember dozens of unique random passwords. A password manager remembers them for you and fills them in, so you only need to remember one strong passphrase for the manager itself. Use the passphrase guide for that one.
What to add on top
- Turn on two-step verification wherever it is offered, ideally with an authenticator app or a security key.
- Never share a password by email or chat.
- Change a password when a service tells you it was breached.
Frequently asked questions
Should I change my passwords regularly?
Routine forced changes tend to produce weaker, predictable passwords, and current NIST guidance advises against requiring them without a reason. Change a password when you suspect it was exposed or when a service reports a breach.