How to Create a Strong Password You Can Remember
Most “strong” passwords aren't: attackers try words with capitals, numbers and a ! first. The good news is that the strongest passwords are also the easiest to remember. Here's the method security experts actually use.
Use a passphrase of 5–6 random words (like “Tidy-Oyster-Gravel-Mango-Lunar”) for passwords you must remember, and let a password manager generate random 16+ character passwords for everything else. Use a different password for every account, never base it on names, dates or keyboard patterns, check it against breach lists, and turn on two-factor authentication.
What makes a password strong
Strength is the number of guesses an attacker needs. Cracking tools don't try random characters first — they try leaked passwords, dictionary words, names, years and common substitutions like @ for a and 0 for o. So “Summer2024!” looks complex but falls almost instantly, while four or five truly random words can take centuries.
Length beats complexity. Each extra random character or word multiplies the work, which is why current NIST guidance recommends long passphrases over forced symbol rules.
The passphrase method (easy to remember)
Pick 5 or 6 words at random — really at random, from a generator or by rolling dice with the EFF word list, not words you choose yourself. Join them with a separator and optionally capitalise them or add a digit: “Canal-Rocket-Wobbly-Tulip-Ember-3”. Picture a scene that links the words and you'll remember it within a day.
Six random words from the 7,776-word EFF list give about 77 bits of entropy — stronger than a random 12-character password. Generate one with the Passphrase Generator.
Examples: weak vs strong
Weak: Password123, Summer2024!, Qwerty!@#, your pet's name with your birth year, P@ssw0rd — all appear in cracking wordlists.
Strong: a random 16–20 character string like u7$Kq!9zR#mW2pLx (for a password manager), or a random 5–6 word passphrase (for anything you type). Never use these exact examples — generate your own.
One password per account
Reusing a password is the biggest real-world risk: when one site is breached, attackers try the same email and password everywhere (credential stuffing). A password manager (Bitwarden, 1Password, your browser's or Google Password Manager) creates and remembers a unique password for every site, so you only need to remember one strong passphrase.
Generate random passwords with the Strong Password Generator, and turn on two-factor authentication for email, banking and social media.
Check a password before you use it
The Password Strength Checker estimates crack time the way attackers work and can check whether a password appears in known breaches without sending it — only a short fragment of its hash leaves your device. If it's been breached, don't use it anywhere.
Try Free Web Tools Mentioned in This Guide
Password Strength Checker
Test how strong your password really is, how long it takes to crack, and whether it's been breached.
Passphrase Generator
Create strong, memorable passphrases from random words (EFF diceware list).
Strong Password Generator
Generate strong, random passwords with the exact length and characters you need.
Password Entropy Calculator
Calculate password entropy in bits — the naive formula and a realistic, pattern-aware estimate.
Frequently Asked Questions
How long should a password be?↓
At least 12 characters for everyday accounts and 16+ for email, banking and your password manager — or a passphrase of 5–6 random words.
How do I create a strong password with only 8 characters?↓
If a site limits you to 8, use a fully random mix of upper and lower case letters, numbers and symbols from a generator, never a word, and turn on two-factor authentication. Eight characters is still weak against offline cracking.
Should I change my passwords regularly?↓
No — change them when there's a reason (a breach or suspected compromise). Forced regular changes lead to weaker, predictable passwords.
Is it safe to use a password manager?↓
Yes, for almost everyone it's far safer than reusing passwords. Protect it with a strong passphrase and two-factor authentication.