Length beats complexity
Every character you add multiplies the number of guesses an attacker needs. A 12-character password drawn from 72 possible characters has about 71 bits of entropy; bump it to 20 characters and you are near 123 bits — a difference between "crackable with serious hardware" and "not crackable before the heat death of the universe." The single highest-leverage change you can make is simply going longer.
Complexity rules like "must contain a symbol" help less than people think, because attackers know the tricks too (everyone substitutes @ for a and ! at the end). Length, on the other hand, cannot be guessed around. Aim for 16 characters minimum for everyday accounts and 20+ for critical ones like email and banking.
Use passphrases you can picture
For the handful of passwords you must memorize — your password manager's master password, your device PIN-adjacent secrets — use a passphrase: four to six random words strung together, like correct-horse-battery-staple. Random word passphrases are both strong (each word adds ~11–13 bits of entropy from a modest word list) and dramatically easier to recall than Tr0ub4dor&3.
The key word is random. "My dog's name is Biscuit 2024" is a sentence, not a passphrase — attackers try exactly those patterns. Use a generator or dice to pick the words, then add a personal twist you will not forget, such as a separator or a final symbol.
One account, one password
The biggest real-world threat is not someone guessing your password — it is credential stuffing. Breaches leak billions of username/password pairs, and attackers automatically replay them on every major site. If your streaming-service password equals your email password, one breach hands over both.
This is why memorization cannot be the strategy: nobody can remember 100 unique 20-character passwords. Generate a fresh random password per site with our password generator and store them in a password manager. You memorize exactly one strong master passphrase; the manager handles the rest.
Mistakes to avoid
- Reusing passwords across sites — the number-one cause of account takeovers.
- Predictable substitutions (
P@ssw0rd!) — password crackers try these first. - Personal details — birthdays, pet names, and addresses are discoverable from social media.
- Rotating passwords on a schedule — forced 90-day changes push people toward weaker, patterned passwords. Change a password when there is evidence of compromise, not on a calendar.
- Writing passwords on sticky notes — unless your threat model is literally only remote attackers, use a manager instead.
Storing and sharing passwords safely
Creating strong passwords is half the job; handling them safely is the other half. The golden rule: passwords live in your manager or nowhere. Never in notes apps, spreadsheets, emails, chat messages, or screenshots — all of these sync to clouds, get backed up indefinitely, and are searchable by anyone who glimpses your screen.
Sharing is the tricky case. Families share streaming logins; teams share service accounts. Do it through your manager's secure sharing feature, which grants access without revealing the password itself — and lets you revoke it later. Texting a password, even "temporarily," leaves a permanent copy in two chat histories and two cloud backups.
Finally, plan for the worst day: set up emergency access so a trusted person can reach critical accounts if you cannot. Most managers offer a delayed-access feature where your designee requests entry and you have, say, 72 hours to decline. It takes ten minutes to configure and prevents the far worse outcome of your digital life becoming permanently inaccessible.
Want the full picture? Read password security myths, debunked next, or compare passphrases vs. random passwords to pick the right style for each situation.