A strong password is long, uses mixed character types, and is unique to each account

A strong password does three things: it is at least 12 characters long, it mixes uppercase letters, lowercase letters, numbers, and symbols, and it is different for every account you use. The length matters most — a 12-character password with mixed types stops most automated attacks. The uniqueness matters because if one website gets hacked, attackers will try that same password on your email, banking, and social media accounts.

The easiest way to create and store strong passwords is to use a password manager like Bitwarden, 1Password, or Dashlane. These programs generate random passwords for you, remember them, and fill them in automatically. You only have to remember one strong master password to unlock the manager itself. If you prefer to create passwords by hand, aim for a phrase you can remember — like "MyDog8AteMyShoes!" — rather than trying to memorize random strings.

Key Takeaways

  • A strong password is at least 12 characters long and includes uppercase letters, lowercase letters, numbers, and symbols mixed throughout.
  • Each account should have its own unique password so that a breach at one website does not expose your other accounts.
  • A password manager stores strong passwords securely and fills them in automatically, so you only need to remember one master password.
  • If you create passwords by hand, use a memorable phrase with mixed character types rather than random letters that are hard to recall.
  • Avoid using personal information like birthdays, pet names, or addresses, because attackers often try these first.

Why length matters more than complexity

A 12-character password with only lowercase letters is harder to crack than an 8-character password with symbols and numbers. This is because password-cracking tools work by trying every possible combination, and each additional character multiplies the number of combinations exponentially. A hacker's computer can try millions of passwords per second, but a 12-character password has trillions of possible combinations.

This is why security researchers now recommend length as the primary defense. A password like "correcthorsebatterystaple" (26 characters, all lowercase) is stronger than "P@ss9!" (6 characters, mixed types). That said, mixing character types does add protection without much extra effort, so doing both — length plus mixed types — is the best approach.

How to create a password you can actually remember

The most memorable passwords come from a phrase that means something to you but would not appear in a dictionary or be guessable from your social media. Take a sentence like "I moved to Portland in 2015 and loved it" and use the first letter of each word: "ImtPi2015ali". Then swap one or two letters for symbols: "ImtPi2015@li". This gives you a 12-character password with mixed types that you can recreate from the same phrase every time.

Avoid using information that appears on your social media or in public records: your pet's name, your child's birth year, your street address, or your favorite sports team. Attackers often start with this information because it is easy to find. Similarly, do not use keyboard patterns like "qwerty" or "123456" — these are among the first things password-cracking tools try.

When and how to use a password manager

A password manager is a program that generates random passwords, stores them encrypted on your device and in the cloud, and fills them into websites automatically. Popular options include Bitwarden (free or paid), 1Password (paid subscription), Dashlane (free or paid), and LastPass (free or paid). Each one works slightly differently, but the core idea is the same: you create one strong master password, and the manager handles the rest.

To set up a password manager, download the program or browser extension, create your master password, and then start using it to generate passwords for new accounts. When you visit a website you have already saved, the manager fills in your username and password automatically. If you switch devices, the manager syncs your passwords across them — so your passwords on your phone match your passwords on your laptop.

The main risk with a password manager is that if someone discovers your master password, they can access all your accounts. This is why your master password should be strong and unique, and why you should never write it down or share it. Most password managers also offer two-factor authentication on the master account itself, which adds a second layer of protection.

How to handle passwords for accounts you cannot change

Some older accounts or systems do not let you change your password, or they require a specific format that does not allow symbols. In these cases, make the password as long as the system allows and use as many character types as it accepts. If a system only accepts letters and numbers, a 16-character password is better than an 8-character one.

For accounts that are less sensitive — like a forum you rarely visit — a weaker password is a lower risk than for accounts that hold money or personal information. Your email and banking passwords should always be strong and unique. Your social media passwords should be strong and unique. A throwaway account on a website you will never use again can be weaker, though a password manager makes it just as easy to use a strong password anyway.

What to do if you think a password has been compromised

If you receive a notification that a website you use has been hacked, change your password on that website immediately. If you used the same password on other accounts, change those too. You can check whether your email address has appeared in a known breach by visiting haveibeenpwned.com and typing in your email address — this site is run by security researcher Troy Hunt and is free to use.

If you used a password manager, you can search it to see which other accounts share that password. Most password managers have a search or audit feature that flags duplicate passwords. If you find duplicates, change them one by one. This is one reason a password manager is useful: it makes it easy to see which accounts share passwords and to change them without having to remember what the old password was.

Frequently Asked Questions

Is it safe to save passwords in my web browser?

Browser password storage (like Chrome's password manager or Firefox's password manager) is encrypted and reasonably secure for most people. However, a dedicated password manager like Bitwarden or 1Password offers stronger encryption and more features. If you are already using your browser's built-in manager and it works for you, it is better than writing passwords down or reusing the same password everywhere.

Should I change my passwords regularly if I have not been hacked?

No. Security experts now recommend changing passwords only when you suspect a breach or when a website asks you to. Changing passwords frequently often leads people to create weaker passwords or write them down, which increases risk. Focus instead on using strong, unique passwords from the start and changing them only when necessary.

What if I forget my master password for my password manager?

Most password managers cannot recover a forgotten master password — it is encrypted so strongly that even the company cannot access it. This is why you should write your master password down and store it somewhere safe, like a locked drawer or a safe deposit box. Some managers offer recovery codes you can print and store separately as a backup.

Can I use the same password for accounts I do not care much about?

It is better not to, because you cannot predict which websites will be hacked or which ones attackers will target. A password manager makes it just as easy to use a unique password for every account, so there is no real downside to doing so. If you must reuse a password, at least keep it off your most important accounts: email, banking, and any account linked to payment methods.

Do I need special characters in my password, or is length enough?

Length is the most important factor, but mixing in uppercase letters, numbers, and symbols makes a password stronger without much extra effort. A 16-character password with only lowercase letters is strong. A 12-character password with mixed types is also strong. A 12-character password with only lowercase letters is weaker than both. Aim for length first, then add mixed types if you can.