Quick Answer
Use a passphrase: four or five unrelated words strung together, at least 16 characters total, with a number and symbol mixed in. Example pattern: Copper-Mango-Riverbed-77. Length beats complexity. Store the rest in a password manager and turn on two-factor authentication everywhere.
Why Most Password Advice Is Wrong
For twenty years people were told to use short, messy passwords like P@ssw0rd7!. That advice came from a 2003 guidance document whose own author later said it was a mistake.
The problem is simple. P@ssw0rd7! is hard for a human to remember and easy for a machine to guess, because cracking software already knows every common substitution: a to @, o to 0, s to $, an exclamation mark at the end.
Modern guidance, including the current NIST recommendations, points in a different direction: make passwords long, stop forcing arbitrary character rules, and stop forcing routine expiry.
What Actually Makes a Password Strong
Three factors decide how long a password survives an attack.
1. Length. Every character you add multiplies the number of possible combinations. Going from 8 characters to 16 does not double the difficulty; it raises it by an enormous factor.
2. Unpredictability. A password must not be derivable from you. Your dog’s name, your birth year, your favourite team, and your registration plate are all public or guessable.
3. Uniqueness. A strong password reused across ten sites is a weak password. When any one of those sites is breached, attackers replay the same email and password combination everywhere else. This attack is called credential stuffing and it is the single most common way ordinary accounts get taken over.
| Password | Length | Why it fails or works |
| sunny123 | 8 | Dictionary word plus sequence. Cracked instantly. |
| P@ssw0rd7! | 10 | Known substitution pattern. Cracked in seconds. |
| Rahul@1995 | 10 | Name plus birth year. Guessable from social media. |
| Copper-Mango-Riverbed-77 | 24 | Long, unrelated words, no personal link. Strong. |
| k7$Lp2!xQm9Vz4Rt | 16 | Random and strong, but impossible to memorise. |
The Passphrase Method, Step by Step
This is the method to use for the handful of passwords you must type from memory: your device login, your email, and your password manager itself.
1. Pick four to five unrelated words
Not a phrase from a song, not a proverb, not a movie title. Those exist in cracking dictionaries. Pick words that have no logical connection to each other.
Good: copper mango riverbed lantern Bad: to be or not to be
2. Join them with a separator
Use a hyphen, underscore, or full stop between words. This adds length and breaks up the word boundaries.
copper-mango-riverbed-lantern
3. Add one number and one capital that mean something to you
Do not put the number at the end where every cracking tool expects it. Drop it in the middle.
Copper-mango-77-riverbed-lantern
4. Check the length
Aim for 16 characters minimum. Twenty or more for email and banking. The example above is 33 characters and still typeable.
5. Say it out loud three times
Memorable passwords are memorable because they produce an image in your head. A copper mango sitting on a riverbed is absurd, which is exactly why it sticks.
Use a Password Manager for Everything Else
You should not try to memorise 80 passwords. You should memorise three or four and let software handle the rest.
A password manager generates a unique random string for every site, stores it encrypted, and fills it in for you. Reputable options include Bitwarden, 1Password, Proton Pass, KeePassXC, and the managers built into Apple, Google, and Microsoft accounts.
What to look for when choosing one:
- Zero-knowledge encryption, meaning the provider cannot read your vault
- A published security audit
- Cross-device sync that works on the devices you actually use
- An emergency access or recovery option
- Export capability, so you are not locked in
Protect the manager itself with a long passphrase built using the method above, plus two-factor authentication.
Two-Factor Authentication Matters More Than Password Complexity
Even a perfect password can be stolen through a phishing page or a keylogger. A second factor stops the attacker at the door.
In order of strength:
- Hardware security key (YubiKey and similar). Strongest, and resistant to phishing.
- Passkeys. A newer standard that replaces passwords entirely using your device biometrics. Adopt these where offered.
- Authenticator app (Google Authenticator, Authy, Aegis, Ente Auth). Strong and free.
- SMS codes. Better than nothing, but vulnerable to SIM swap fraud.
If a service offers only SMS, still turn it on. Then ask your mobile operator to add a port-out PIN on your number.
Mistakes to Avoid
- Reusing one password across sites. The single riskiest habit in personal security.
- Storing passwords in a browser without a master password set. Anyone with access to your unlocked laptop has your accounts.
- Keeping passwords in a Notes file, Excel sheet, or WhatsApp message to yourself. All unencrypted.
- Changing passwords every 30 days for no reason. Forced rotation pushes people toward predictable patterns like Summer2026! then Autumn2026!. Change a password when there is a reason: a breach, a shared device, or a suspicion.
- Answering security questions honestly. Your mother’s maiden name is findable. Treat security answers as secondary passwords and store random answers in your manager.
- Ignoring breach alerts. If a site tells you it was breached, change that password immediately and anywhere you reused it.
Pro Tips
- Check your email address on Have I Been Pwned to see which breaches already include you.
- Give your email account your strongest password. It is the reset route into everything else.
- Turn on passkeys wherever they appear. Fewer passwords to protect is better than stronger passwords.
- Print your password manager recovery code and keep it somewhere physically safe.
- Set up emergency access so a trusted person can reach critical accounts if something happens to you.
Frequently Asked Questions
How long should a strong password be in 2026?
Aim for at least 16 characters for everyday accounts and 20 or more for email, banking, and your password manager. Length is the single biggest factor in resistance to brute-force cracking, and a long passphrase made of ordinary words is easier to remember than a short random string.
Are passphrases really safer than complex passwords?
Yes, when they are long enough and made of unrelated words. A 24-character passphrase has far more possible combinations than a 10-character password with symbols. The one condition is that the words must not form a known phrase, quote, or song lyric, since those appear in cracking dictionaries.
Is it safe to store passwords in my browser?
It is safer than reusing passwords, but weaker than a dedicated password manager. Browser stores are tied to a single ecosystem, offer fewer sharing and auditing features, and can expose credentials if someone gains access to your unlocked device. If you do use one, protect the browser profile with a strong device login.
How often should I change my password?
Only when there is a reason. Change immediately after a breach notification, after sharing the password with anyone, after using it on a public computer, or if you suspect compromise. Routine scheduled changes tend to make passwords weaker because people fall into predictable patterns.
What is a passkey and should I use one?
A passkey replaces a password with a cryptographic key stored on your device and unlocked by your fingerprint, face, or device PIN. There is nothing to type, so there is nothing to phish. Where a service offers passkeys, they are the safest option available to a normal user.
What should I do if my password was in a data breach?
Change that password immediately, change it anywhere else you used the same one, turn on two-factor authentication for the affected account, and review recent login activity. If the breached account was your email, check that no forwarding rules or recovery addresses were added without your knowledge.

