How to Create a Strong Password You Can Actually Use
Published 2026-10-01
Most account hacks happen because of weak or reused passwords, not clever attacks. A few simple habits protect you far better than complicated tricks.
What makes a password strong
- Length: at least 12 characters, ideally 16 or more.
- Randomness: not a name, birth year or keyboard pattern.
- Uniqueness: a different password for every important account.
Length matters more than special characters. A long random password is much harder to crack than a short one full of symbols.
Passwords to avoid
- 123456, password, qwerty and similar common choices.
- Your name, phone number or date of birth.
- The same password reused on several sites.
- Small changes like Password1 and Password2.
Use a generator instead of inventing one
Humans are bad at being random. Use our Password Generator to create a password of 16 or more characters. It uses your browser secure random source and never stores or sends the result.
How to remember many passwords
Nobody can memorise dozens of random passwords. Use a reputable password manager and protect it with one strong master password. Many browsers also include a built-in manager.
Turn on two-factor authentication
Two-factor authentication adds a second step, such as a code from an authenticator app. Even if someone learns your password, they cannot log in without it. Enable it first on your email, banking and social media accounts.
What to do after a data breach
- Change the password on that site immediately.
- Change it anywhere else you reused it.
- Check for unfamiliar logins.
- Enable two-factor authentication.