Most advice about passwords is a decade out of date. Forcing a capital letter, a number and a symbol into an eight-character word does far less than simply making the password longer. Here is what genuinely matters.
Length is the single biggest factor
Every extra character multiplies the number of possible combinations. A random 16-character password is astronomically harder to brute force than a clever eight-character one. If you remember one rule, make it this: aim for 16 characters or more.
Reuse is what actually gets people hacked
Attackers rarely crack your password. They buy a leaked list from a breached website and try the same email and password combination everywhere else. That technique is called credential stuffing, and it only works because people reuse passwords. One unique password per account defeats it entirely.
Predictable patterns are weak, even if they look complex
- Substituting letters with symbols such as P@ssw0rd is in every cracking dictionary.
- Adding a year or an exclamation mark at the end is the first thing tools try.
- Names, birthdays and team names are guessable from your social profiles.
Use a generator and a manager together
Generate a long random password with our Password Generator, which uses your browser's cryptographic random source and never sends the result anywhere, then store it in a password manager. You only have to remember one strong master passphrase after that.
Turn on two-factor authentication
Even a perfect password can be phished. An authenticator app adds a second barrier that stops almost every automated attack. Enable it on email, banking and social accounts first — those are the keys to everything else.