How to Choose a Strong Password or Passphrase

Choose a long, randomly generated password, use it for one account only, and save it in a password manager. If you need to remember it, use several independently selected random words. A password does not need to look like spilled alphabet soup to be difficult to guess.

Our password and passphrase generator starts with 24 random characters or six random words. Both are practical starting points when the destination accepts their length.

Why a passphrase can be stronger than a complicated password

P@ssw0rd! looks complicated to a person. To guessing software, it is a familiar word with familiar substitutions. Attackers can try dictionary words, leaked passwords, names, dates, and predictable variations before trying every possible character combination.

A random passphrase works differently. Imagine a tiny cartoon: an otter drives a tractor past a velvet cactus. That picture may help you remember words after they have been selected randomly. Inventing the picture first and choosing words to fit it does not provide the same randomness. Four words are just a short demonstration here; use a longer phrase for an important secret.

With our adapted long list, every independently chosen word multiplies the number of possible phrases by 7,772. Six random words have about 77 bits of randomness: roughly 220 sextillion possible phrases. An attacker can know the word list and separator and still face that many combinations. Fixed capitalization and punctuation do not increase this word-selection count.

EFF recommends at least six randomly selected words for secrets such as a password-manager or disk-encryption password. A favorite lyric, famous quotation, or personal sentence is not equivalent, however long it looks.

Length and unpredictability matter more than satisfying a checklist of symbols. NIST’s authentication guidance requires services following its rules to accept password managers and prohibits composition rules that force mixtures of character types. It also requires at least 15 characters for passwords used as a single authentication factor, with an eight-character minimum permitted when a password is part of multi-factor authentication. These are service requirements, not a claim that every 15-character phrase is strong.

Password examples: from open door to serious obstacle

Every example below is public. Never use one as an actual password. The ratings describe the selection method and length, not a safety certificate for the printed string.

For the random rows, the table imagines an attacker with a stolen password hash who can test one billion guesses per second. This is a hypothetical constant rate, not a benchmark for any device or password-storage algorithm. The attacker knows the generation method and tests distinct candidates. The time is the average over uniformly random choices: approximately half the possibilities divided by the guessing rate. A lucky first guess is always possible.

Example you must not useHow it was chosen for this comparisonStrength at this settingAverage time at 1 billion guesses/second
P@ssw0rd!A common word with predictable substitutions Very weakNo defensible fixed time; a likely early dictionary candidate.
804271Six uniformly random digits Very weak0.0005 seconds - barely a blink.
qmvztrkaEight uniformly random lowercase letters WeakAbout 1 minute 44 seconds - a short tea break.
otter-tractor-velvet-cactusFour independent choices from 7,772 words LimitedAbout 21 days - longer, but add words.
r7K2v9Q4m6Z8Twelve uniform choices from 62 letters and digits StrongAbout 51,000 years.
otter-tractor-velvet-cactus-hammock-lanternSix independent choices from 7,772 words Very strongAbout 3.5 million years.
r7K2v9Q4m6Z8b3W5Sixteen uniform choices from 62 letters and digits Very strongAbout 755 billion years.

The samples are illustrations of those formats, not evidence that their printed characters were randomly selected. The six-digit example models a PIN; it is not an option for a six-character password in our generator. The letter-and-digit rows allow every combination and do not impose required character groups.

How to read the numbers without being misled

For eight lowercase letters, the calculation is 26^8 / (2 × 1,000,000,000), or about 104 seconds. For six words it is 7772^6 / (2 × 1,000,000,000). These calculations count choices; they do not measure actual cracking software.

At 1,000 guesses per second, every numerical time in the table would be one million times longer. At one trillion guesses per second, it would be one thousand times shorter. Large year counts express the size of a search space under fixed assumptions; they are not forecasts about future computing or how long an account will remain safe.

An online attack tries a website’s login form, where rate limits, lockouts, and multi-factor authentication can restrict attempts. An offline attack tests guesses against stolen hashes without asking the website. Password storage matters enormously: deliberately costly algorithms such as Argon2id and bcrypt make each guess more expensive than a fast hash. OWASP’s password-storage guide explains that distinction and the role of work factors.

No cracking-time table accounts for a password stolen by phishing, malware, or reuse after another site is breached. Those attacks do not need to search the full space.

Common password mistakes

  • Reusing one good password. If it leaks from one account, attackers can try it elsewhere. Adding a site’s name or changing only the final digit is still a predictable system.
  • Using personal trivia. Pet names, birthdays, favorite teams, and information on social profiles make useful guessing material.
  • Decorating a weak word. Password1! passes many complexity rules without becoming a good secret.
  • Choosing a long quotation. Familiar sentences belong in dictionaries too. Random words should be selected independently, not taken from a book or song.
  • Trimming a generated password. Choose compatible settings before generating it. If symbols are rejected, use a longer letters-and-numbers password rather than cutting it down.
  • Treating a strength meter as proof. A meter cannot know every leaked or personally significant string. The method used to generate a password matters more than its appearance.
  • Replacing a strong password with a predictable monthly variation. Change a password when it is exposed, reused, or suspected compromised, and follow any applicable account policy. Generate a completely new secret.

Let a password manager do the remembering

For everyday logins, a manager lets you use a different random password for every account without memorizing them all. Consider Bitwarden for a free personal option with syncing, 1Password for paid personal or family plans, or Proton Pass for password management with email aliases. If you prefer controlling a local encrypted vault file, KeePassXC is a free desktop option; plan your own backup and device-sync arrangements.

Protect the manager with a unique random passphrase and multi-factor authentication where supported. Keep its recovery material somewhere safe that you can access if you lose your normal device. Read the provider’s recovery instructions before you need them. You can use its built-in generator for account creation or save a fresh result from our password generator.

For accounts offering passkeys, consider them: FIDO explains how passkeys resist phishing. When a password is still required, enabling a second factor adds protection beyond the password itself.

Make your next password a better one

  1. Start with important accounts: primary email, your password manager, and financial accounts. Replace reused passwords first.
  2. Generate a fresh secret: use a long random password for autofill, or six or more long-list words when memorization matters.
  3. Save it and update the account: generation alone does not change an existing login. Confirm the new credential works and keep recovery options current.
  4. Enable additional protection: use multi-factor authentication or a passkey where offered.

For a website’s protected directory, create the secret first and then use our Apache htpasswd generator to produce the stored hash. For a guest network, change the router password and then create a Wi-Fi QR code. Check their length limits before choosing a long phrase.

If you want to inspect how an online tool handles data, our guide to checking website network requests walks through Chrome, Firefox, Edge, and Safari. Use harmless sample data when investigating; do not test unfamiliar sites with a real password.

Premium is coming soon

An optional premium subscription to remove ads is planned. Subscriptions are not available yet.

You can keep using our free tools without an account.