Most of us were taught that a strong password needs a capital letter, a number and a symbol, and should change every 90 days. That advice produced passwords like Summer2026!: technically compliant, easy to guess, and quickly forgotten. Modern guidance has moved on. What matters most is length and unpredictability, and the easiest way to get both is to stop choosing passwords yourself.
How passwords are actually cracked
Understanding the attacks explains the advice. There are three main routes:
- Credential stuffing. Attackers take usernames and passwords leaked from one breached website and try them on many others. If you reuse a password, its strength is irrelevant: it is already known.
- Online guessing. Automated attempts against a live login page, trying common passwords. Rate limiting and account lockouts slow this down a great deal.
- Offline cracking. When a database of password hashes is stolen, attackers can test billions of guesses per second on their own hardware, without any lockout. This is where length really counts.
Cracking tools do not guess letter by letter at random. They start with leaked password lists, dictionary words, names, dates and keyboard patterns, then apply common tweaks: capitalize the first letter, swap a for @ and o for 0, add a year and an exclamation mark at the end. Those "clever" substitutions are exactly what the software tries first.
Why length beats complexity
Password strength is often described in bits of entropy, a measure of how many guesses a truly random password would take. Each extra bit doubles the work. The numbers below assume the password was generated randomly, not chosen by a person:
| Password style | Example shape | Approximate entropy |
|---|---|---|
| 8 random characters from all 94 keyboard symbols | k#9Tq!2z | About 52 bits |
| 16 random lowercase letters | qmvrtzlpaekdhwsy | About 75 bits |
| 6 random words from a 7,776-word list | cactus-ladder-ripple-onion-vivid-maple | About 77 bits |
| 20 random characters from all 94 symbols | (from a generator) | About 131 bits |
Sixteen plain lowercase letters beat eight characters of "full complexity" by a wide margin, because every added character multiplies the possibilities. Length is also kinder to people: a long phrase is easier to type and remember than a short jumble of symbols.
This is reflected in the U.S. National Institute of Standards and Technology (NIST) Digital Identity Guidelines, SP 800-63B, which many organizations use as a reference. They recommend favouring length, allowing long passwords and spaces, checking new passwords against lists of known-breached ones, and dropping forced composition rules and routine expiry. Passwords should be changed when there is evidence of compromise, not on a calendar.
Three ways to create a strong password
1. Let a generator do it (best for most accounts)
Humans are bad at randomness. A password generator is not. Use the generator built into your password manager, or our free password generator, and aim for 16 characters or more. You never need to remember these; the password manager stores and fills them.
2. Use a random passphrase (for the few you must memorize)
You still need a handful of passwords in your head: your computer login, your password manager's master password, perhaps your phone. For these, a passphrase of five to seven randomly chosen words works well. The word "randomly" is critical. A song lyric, a famous quote or "ilovemydog" are in cracking dictionaries. Pick words by rolling dice against a published word list (the "Diceware" method) or use a generator that produces word-based passphrases.
3. Never build passwords from a pattern
Schemes like "site name plus my base password" (Amazon-Rover2019, Gmail-Rover2019) feel unique but are not. Once one leaks, the pattern is obvious to anyone who looks.
Rules that matter more than strength
- Never reuse a password. Reuse is the single biggest risk, and no amount of complexity fixes it.
- Use a password manager so unique passwords for every account are practical.
- Turn on two-factor authentication for email, banking, cloud and admin accounts. Even a perfect password can be phished.
- Change a password immediately if a service you use reports a breach, or if you typed it into a suspicious page.
- Protect your email account above all. It can reset most of your other passwords.
For administrators setting a password policy
- Set a generous minimum length (many organizations now choose 12 to 15 characters) and allow at least 64 characters.
- Allow all printable characters, including spaces, and permit pasting so password managers work.
- Block passwords that appear in breach lists and obvious choices like the company name.
- Drop mandatory complexity rules and scheduled expiry; they push people towards predictable patterns.
- Store passwords only as salted hashes using a slow algorithm designed for passwords, such as Argon2id, scrypt or bcrypt. Never store them in plain text or with a fast hash like MD5.
- Rate-limit login attempts and require two-factor authentication for privileged accounts.
If your business runs its own customer login, check how that system stores passwords during any web application upgrade; older code often uses outdated hashing. OWASP's Password Storage Cheat Sheet covers the hashing side in detail for developers.
Key takeaways
- Length and randomness make a password strong; symbol substitutions add little.
- Use generated passwords for everything, and random multi-word passphrases for the few you memorize.
- Never reuse passwords; a password manager makes that achievable.
- Combine strong passwords with two-factor authentication on important accounts.