How to Create and Manage Strong Passwords

Last updated: 8 October 2026

Most account break-ins are not clever hacks. They happen because a password was short, reused or leaked in a data breach somewhere else. A few habits remove most of the risk.

Length beats complexity

Every extra character multiplies the number of guesses an attacker needs. A random password of 16 characters is vastly stronger than an 8-character one full of symbols. A passphrase of four or more unrelated words, such as "river-plastic-lantern-ocean", is also strong and easier to remember. You can test the effect with the Password Strength Checker using a similar example instead of your real password.

Use a different password for every account

When a website is breached, attackers try the leaked email and password on other sites. If you reuse passwords, one leak opens many doors. Unique passwords limit the damage to one account.

Let a tool remember them

Nobody can memorise dozens of random passwords, which is what password managers are for. Create one strong master passphrase, and let the manager generate and fill the rest. The Password Generator creates random passwords in your browser with the secure random number generator, and nothing is sent anywhere.

Add a second factor

Two-factor authentication means that a stolen password is not enough. Prefer an authenticator app or a hardware key over SMS where possible. Turn it on first for email, banking and any account that can reset others.

Avoid these mistakes

Related developer concepts

If you build websites, never store passwords in plain text or with a fast hash alone. Use a slow, salted algorithm such as bcrypt, scrypt or Argon2. The Hash Generator demonstrates how a tiny input change creates a completely different hash, but hashes made there are not a substitute for proper password storage.