How to create a strong password (and why length matters most)

Most advice about passwords was written for a world where people memorized a handful of them. Today the average person has dozens of accounts, and the biggest risks are reused passwords and passwords short enough to guess. Here is what actually makes a password strong, and a simple system for keeping all of them safe.

How passwords get broken

  • Reuse after a breach. When a website is breached, its list of email addresses and passwords often ends up online. Attackers then try those same combinations on email, banking and shopping sites. This “credential stuffing” is the most common way accounts are taken over, and no amount of complexity helps if the password was reused.
  • Guessing. Attackers try common passwords, dictionary words, names, dates and predictable substitutions (P@ssw0rd) first, because people choose them so often.
  • Brute force. If attackers get hold of a site’s scrambled (hashed) passwords, they can test billions of guesses per second on their own hardware. Only long, random passwords are out of reach.
  • Phishing. A fake login page simply asks for the password. Strength doesn’t matter here, which is why two-step verification is so important.

Measuring strength: entropy

The strength of a randomly generated password is measured in bits of entropy: the number of times you would have to double the number of guesses to cover every possibility. It depends on two things, the size of the character set and the length:

entropy = length × log2(number of possible characters)

Characters usedPool sizeBits per character12 characters20 characters
Digits only103.340 bits66 bits
Lowercase letters264.756 bits94 bits
Upper and lowercase, digits626.071 bits119 bits
All printable keyboard characters946.679 bits131 bits

The table shows why length matters more than complexity: adding symbols to a 12-character password gains about 8 bits, while making a lowercase password 8 characters longer gains about 38. Every extra character multiplies the work for an attacker. Around 80 bits is beyond the reach of any realistic guessing attack today, and 100 bits or more leaves a wide safety margin.

One important catch: these numbers only apply to passwords chosen at random. A 12-character password like “Summer2026!!” has nowhere near 79 bits, because attackers guess patterns like that early.

What the experts recommend now

The US National Institute of Standards and Technology (NIST) publishes digital identity guidelines (SP 800-63B) that many organizations follow. The current guidance focuses on length, recommending that passwords used without a second factor be at least 15 characters, and that sites accept long passwords of 64 characters or more. It advises sites not to force mixtures of character types or regular password changes, which push people toward predictable patterns, and instead to check new passwords against lists of breached and common passwords.

A simple system that works

  1. Use a password manager. The managers built into Apple devices, Google Chrome and Android, and Microsoft Edge are free, and dedicated apps add features like sharing. A manager remembers every password, fills it in for you, and won’t fill it in on a look-alike phishing site.
  2. Give every account its own random password. Let the manager generate one, or use Wordformat’s password generator, which creates passwords on your own device with your browser’s cryptographic random number generator. 16 to 20 characters is a good default.
  3. Memorize only a few, and make them passphrases. You need to remember your device passcode, your password manager’s main password and perhaps your email password. For those, use four to six random words, such as “orbit lantern cactus mild velvet”. Choose the words randomly (with dice or a generator), not from a favorite quote. Each word chosen from a list of 7,776 words adds about 12.9 bits, so six words gives about 77 bits.
  4. Turn on two-step verification for email, banking and social accounts. An authenticator app or a passkey is stronger than a text-message code.
  5. Use passkeys where offered. Passkeys replace the password with a key stored on your device, and they can’t be phished or reused.

Common questions

Should I change my passwords regularly? Not on a schedule. Change a password when you have reason to think it was exposed, for example after a breach notice.

Is it safe to write passwords down? A paper list kept at home is safer than reusing one password everywhere, because a remote attacker can’t read it. A password manager is better still.

Are security questions safe? Answers like your first school are often findable online. Treat them as extra passwords: give a random answer and store it in your password manager.