A strong password is long, uses mixed character types, and is different for each account you own

The passwords that actually stop attackers are at least 12 characters long, mix uppercase and lowercase letters with numbers and symbols, and are unique to each site. A password like MyDog!Runs#2024 is stronger than password123 because it uses more types of characters and is harder to guess. But the real protection comes from making each password different — if one site gets hacked, attackers won't be able to use that password on your email, banking, or social media accounts.

Most people cannot remember 20 different 12-character passwords, and trying to do so leads to weaker passwords or reusing the same one everywhere. That is why password managers exist: they store all your passwords in an encrypted vault that you unlock with one strong master password. This is not a perfect system, but it is far better than the alternatives.

Key Takeaways

  • A strong password is at least 12 characters long and includes uppercase letters, lowercase letters, numbers, and symbols.
  • Using the same password across multiple accounts means one breach compromises all of them, so each account should have its own password.
  • Password managers like Bitwarden, 1Password, or Dashlane store encrypted passwords so you only need to remember one strong master password.
  • Passphrases — random words strung together like correct-horse-battery-staple — are easier to remember and equally strong if they are long enough.

Why length matters more than complexity

A 16-character password made of only lowercase letters is harder to crack than a 10-character password with symbols and numbers. This is because attackers use automated tools that try millions of guesses per second, and the number of possible combinations grows exponentially with each added character. A password with 16 characters has roughly 4 billion times more possible combinations than one with 12 characters, even if both use the same character types.

This is why passphrases work so well: correct-horse-battery-staple is 34 characters long (including hyphens) and uses only lowercase letters and hyphens, yet it would take a modern computer thousands of years to guess through brute force. You can create a passphrase by picking four or five random words and connecting them with hyphens or spaces. The words should be random to you — not words from a song lyric or a famous quote — because attackers have lists of common phrases.

How to create passwords you can actually use

If you are creating a password you need to type regularly — like your email or banking password — use a passphrase. Pick four unrelated words, write them down with hyphens between them, and you have something both strong and memorable. Examples: purple-elephant-kitchen-tuesday or lamp-forest-number-seven. The words do not need to make sense together.

For every other account, use a password manager. Open the manager, go to the account you are signing up for, and let the manager generate a random password. The manager will store it automatically, so you never need to type it or remember it. When you log in later, the manager fills in the password for you. Most managers work on phones and computers, so you can access your passwords from anywhere.

If you do not yet have a password manager, start with one that is free or low-cost: Bitwarden costs nothing for the basic version and stores passwords on your device and in encrypted cloud backup. 1Password and Dashlane charge monthly but include extra features like breach monitoring. LastPass is free but has had security issues in recent years, so it is not the best choice for new users.

Setting up a password manager

Download the password manager to your computer or phone from its official website or app store. Create an account with a strong master password — this is the one password you will need to remember, so use a passphrase. Write it down and store it somewhere safe, like a locked drawer or a safe deposit box, until you are sure you will not forget it.

Once you are logged in, the manager will offer to scan your existing passwords and import them. Let it do this. Then, the next time you log into any account, the manager will ask if you want to save the password. Say yes. Over time, your manager will collect all your passwords in one encrypted place.

When you create a new account anywhere, use the manager's password generator to create a random password, let the manager save it, and you are done. You do not need to think about password strength anymore — the manager handles it.

What to do if you think a password has been compromised

If you receive a notice that a website you use has been hacked, or if you see your email address on a breach notification site like Have I Been Pwned, change the password for that account immediately. Log into the site, go to settings or account security, and change your password to something new. Use your password manager to generate a new random password.

If you used the same password on other accounts, change those too. This is why unique passwords matter: if you had used the same password everywhere, you would need to change it on dozens of accounts. With unique passwords, you only change the one that was exposed.

Some password managers include a breach monitoring feature that alerts you when one of your passwords appears in a known breach. If your manager has this feature, turn it on. It will not prevent a breach, but it will tell you quickly so you can change the password before an attacker uses it.

Common mistakes that weaken passwords

Do not use personal information in your passwords: not your birthday, your child's name, your pet's name, or your address. Attackers run these details through password-cracking tools because they are easy to find on social media or public records. A password like Sarah1990!Dog looks strong but is actually weak because all three pieces of information are guessable.

Do not reuse passwords across accounts, even if you change one character. If a site is hacked and your password is exposed, attackers will try that password on your email, banking, and social media accounts. They often succeed because people change only one number or symbol between accounts. A password manager solves this problem entirely.

Do not write passwords down on sticky notes or in an unencrypted document on your computer. If someone gains access to your computer or desk, they can read them. A password manager encrypts your passwords, so even if someone steals your computer, they cannot read the passwords without your master password.

Frequently Asked Questions

Is a 12-character password really enough?

For most accounts, yes. A 12-character password with mixed character types would take a modern computer millions of years to crack through brute force. For high-value accounts like email or banking, 16 characters is better, but 12 is a solid baseline. Length matters more than complexity, so a 16-character passphrase is stronger than a 12-character mix of symbols and numbers.

What if a website does not allow special characters in passwords?

Use a passphrase with hyphens or spaces instead. If the site does not allow those either, use uppercase and lowercase letters plus numbers. The site's password rules are usually a sign of poor security practices, so consider whether you really need an account there. If you do, a long passphrase of random words is still stronger than a short password with symbols.

Should I change my passwords regularly if I have not been hacked?

No. Changing passwords regularly does not improve security if the passwords are already strong and unique. Change a password only when you suspect it has been compromised, when a site you use has been breached, or when you think someone else knows it. Forcing regular changes actually makes passwords weaker because people choose simpler ones they can remember.

Can I use the same password manager password on multiple devices?

Yes, that is the whole point. Your master password unlocks your vault on your phone, computer, and tablet. The vault itself is encrypted, so even if someone steals one of your devices, they cannot read your passwords without the master password. Just make sure your master password is strong and unique.

What happens if I forget my password manager master password?

Most password managers cannot recover it for you — the encryption is designed so that even the company running the service cannot read your vault. Some managers offer account recovery options if you set them up in advance, like a recovery code you store separately. Check your manager's recovery options before you need them, and store any recovery codes in a safe place.