A strong password is long, mixed with different character types, and unique to each account

A strong password stops someone from guessing their way into your email, banking, or social media accounts. The difference between a weak password and a strong one is the difference between a lock a child can pick and one that takes serious time and tools to break. Most hackers don't target you personally — they run automated programs that try thousands of common passwords per second. A password that is long and uses a mix of uppercase letters, lowercase letters, numbers, and symbols defeats those programs almost instantly.

The goal is to make your password hard to guess and hard to crack with a computer. That means avoiding birthdays, pet names, dictionary words, and patterns like "123456" or "qwerty". It also means not reusing the same password across multiple sites, because if one site gets hacked, someone with your password can try it everywhere else you have an account.

Key Takeaways

  • A strong password is at least 12 characters long and includes uppercase letters, lowercase letters, numbers, and symbols.
  • Avoid using real words, birthdays, names, or keyboard patterns — these are the first things automated password-cracking tools try.
  • Never use the same password on more than one site, because a breach at one company gives hackers access to all your accounts.
  • A password manager stores unique strong passwords for each account so you only have to remember one master password.
  • If you must write a password down, keep it in a locked drawer at home, not in a note on your computer or phone.

The anatomy of a strong password

A strong password has four ingredients: length, variety, randomness, and uniqueness. Length matters most — a 12-character password is exponentially harder to crack than an 8-character one. Variety means mixing uppercase letters (A-Z), lowercase letters (a-z), numbers (0-9), and symbols (!@#$%^&*). Randomness means the characters don't follow a pattern you can guess or a word you can look up. Uniqueness means you don't use the same password twice.

Here are examples of weak passwords and why they fail:

  • Password123 — Too short, uses a common word, and the number pattern is obvious.
  • Fluffy2024 — A real word (your pet's name) plus the current year. Hackers try pet names and recent years first.
  • qwerty!@# — Follows the top row of your keyboard. This is one of the first patterns automated tools try.
  • MyBirthday1985 — Contains your actual birthday, which is public information on social media.

Here are examples of strong passwords:

  • 7mK$9xL2@qR4vP — 14 characters, random mix of uppercase, lowercase, numbers, and symbols. No pattern, no words.
  • Tr0pic@lThund3r!Sq — 19 characters, mixes character types, but uses words. Still strong because of length and the symbol in the middle.
  • B9#nQ2$wX5&yM7!pL — 17 characters, completely random, very hard to crack.

How to create a password you can actually remember

The easiest strong passwords to remember are ones you create using a system. One method is to take a sentence you know well and use the first letter of each word, then add numbers and symbols. For example, the sentence "My dog ate three socks on Tuesday" becomes "Mdat3soT". Then add a symbol and a number tied to something only you know: "Mdat3soT!9" (if 9 is meaningful to you). This creates a password that is random-looking but memorable to you.

Another method is to pick two unrelated words, combine them with a number and symbol in the middle, and make one word uppercase. For example, "elephant" and "telescope" become "Elephant#7telescope". This is 20 characters, mixes cases and symbols, and is easier to type than a completely random string.

The catch with memorable passwords is that they are usually shorter or more patterned than truly random ones. If you use this method, aim for at least 14 characters and include at least one symbol and one number. If you cannot remember a password that long, use a password manager instead — it is more secure than a weak password you can remember.

Using a password manager to store unique passwords

A password manager is a program that stores all your passwords in an encrypted vault. You create one strong master password to unlock the vault, and the manager remembers everything else. When you visit a website, the manager can fill in your username and password automatically. This solves the problem of remembering dozens of unique strong passwords.

Common password managers include Bitwarden (free and paid versions), 1Password, LastPass, and Dashlane. Most have free versions that work on your computer and phone. When you set up a password manager, it usually has a tool to generate random strong passwords for you — you do not have to create them yourself. The manager stores them encrypted, so even if someone steals your computer, they cannot read the passwords without your master password.

The trade-off is that your master password becomes critical. If someone learns your master password, they can access all your accounts. So your master password should be even stronger than a regular password — at least 16 characters, completely random or based on a long sentence, and never written down or shared.

Changing passwords after a breach

If a website you use gets hacked, change your password on that site immediately. If you used the same password on other sites, change it on all of them. You can check whether your email address has appeared in a known breach by visiting haveibeenpwned.com and typing in your email. This site does not store your information — it only tells you whether your email has shown up in public breach databases.

After a breach, you do not need to change passwords on sites that were not hacked. Changing your password on unaffected sites does not hurt, but it is not necessary unless you reused that password somewhere else. The priority is the sites where you used the same password as the breached site.

What to do if you forget your password

Every major website has a "Forgot Password" link on the login page. Click it, and the site will send a reset link to your email address. Click the link in that email, and you can create a new password. This process usually takes a few minutes. Keep your email account secure because anyone who controls your email can reset passwords on any account tied to that email.

If you forget your password manager's master password, you are locked out of all your stored passwords. Most password managers have a recovery option, but it requires you to have saved a recovery code when you first set up the account. If you use a password manager, save that recovery code in a safe place — a locked drawer, a safe deposit box, or a trusted family member's home. Do not store it on your computer or phone.

Passwords on shared computers and phones

If you share a computer or phone with family members, do not save your passwords in the browser. Anyone who uses that device can see saved passwords in the settings. Instead, type your password each time, or use a password manager that requires your master password to unlock. If you must share a device, create a separate user account for yourself so your files and passwords are not visible to others.

On a shared phone, be especially careful with apps that stay logged in. If you download a banking app and stay logged in, anyone who picks up your phone can access your account. Log out after each use, or use a password manager that requires a master password to show stored credentials.

Frequently Asked Questions

How long should my password actually be?

At least 12 characters, ideally 16 or more. A 12-character password with mixed character types is strong enough for most accounts. For critical accounts like email or banking, aim for 16 characters or longer. Length matters more than complexity — a 20-character password with only lowercase letters is stronger than a 10-character password with symbols.

Is it okay to write my password down?

Only if you keep it in a locked drawer at home, not on a sticky note on your monitor or in a note on your phone. Writing passwords down is less secure than using a password manager, but it is safer than reusing the same weak password everywhere. If you write passwords down, keep the list in a secure physical location and do not include the website name next to each password — write a hint only you understand.

Should I change my passwords regularly if I have not been hacked?

No. Changing passwords regularly does not make you more secure if you have not been breached. Change your password only when you suspect it has been compromised, after a breach at a site you use, or if you shared it with someone. Forcing regular changes often leads people to weaker passwords or patterns, which actually reduces security.

Can I use the same password if I change one character each time?

No. Variations of the same password are still the same password. If someone learns your base password, they can guess the variations. Each account should have a completely different password, not a slight modification of one master password. A password manager makes this easy because you do not have to remember them.

What if a website will not let me use a strong password?

Some older websites have outdated password rules that limit length or forbid symbols. Use the strongest password that site allows, and make sure it is unique to that site. If the site allows at least 12 characters and numbers, you can create a strong password. If it limits you to 8 characters with no symbols, use a unique password anyway — the uniqueness matters more than the strength in this case, because if that site is breached, you do not want the same weak password on other sites.