How to Create a Strong Password (and Why Length Beats Complexity)

For years we were told to mix capital letters, numbers and symbols. The result was passwords like P@ssw0rd1, which are hard for people to remember and easy for computers to guess. Current guidance from standards bodies focuses on something simpler: length and uniqueness.
Why length matters most
Attackers try guesses at enormous speed. Each extra character multiplies the number of possibilities they must try. A long password made of random words is far harder to crack than a short one full of symbols, and it is easier to type and remember.
Use a passphrase
A passphrase is several unrelated words joined together, such as “copper lantern river cabin”. Pick words randomly rather than using a quote, song lyric or something personal. Four to six random words make a strong master password for a password manager, and you can add a separator or number if a site demands it.
What to avoid
- Names, birthdays, pet names and sports teams.
- Common substitutions such as swapping “a” for “@”.
- Keyboard patterns like qwerty or 123456.
- Reusing a password on more than one site, even a strong one.
- Adding a number to the end of an old password each time you change it.
Let a manager do the rest
For everything except your master password and device unlock, let a password manager generate long random passwords of 16 characters or more. You never need to remember them.
Should you change passwords regularly?
Modern guidance says no, unless there is a reason. Forced regular changes lead people to choose weaker, predictable passwords. Change a password when a site reports a breach, you suspect someone has accessed the account, or you used it on a shared device.
Quick checklist
- At least 14 to 16 characters for important accounts.
- Unique for every account.
- Stored in a password manager.
- Protected with two-factor authentication.


