Everyday guide
How to Create a Strong Password You Can Actually Remember
Updated 27 September 2026 · 3 min read
Most accounts are not hacked by someone guessing your password. They are broken into because the same password was reused on a site that was breached, or because it was short enough for a computer to try every combination. A few simple habits make you far safer than most people online.
Open the free Strong Password GeneratorWhat makes a password strong?
- Length. Every extra character multiplies the number of possible combinations. Aim for at least 12–16 characters, and more for important accounts.
- Randomness. Passwords based on names, dates, sports teams or keyboard patterns (qwerty, 123456) are tried first by attackers.
- Uniqueness. A password used on only one site cannot be used against you when a different site is breached.
Why length beats complexity
“P@ssw0rd!” looks complex, but attackers know every common substitution. A long, random passphrase such as “marble-ocean-tractor-violet” is far harder to crack and much easier to type and remember. Current guidance from security agencies favours long passphrases over short passwords with forced symbols.
Two ways to make a strong password
1. Generate one
The Strong Password Generator creates long random passwords using every character type — ideal for banking, email and admin accounts saved in a password manager. The Password Generator lets you choose the length and which characters to include.
2. Build a passphrase
For the few passwords you must type from memory — your computer login or password manager — choose four or more random, unrelated words. Randomness is the key: “sunny-beach-holiday-fun” is a phrase people might pick; “lantern-pickle-orbit-meadow” is not.
Never reuse passwords
When a website is breached, attackers try the leaked email and password combinations on email, banking and shopping sites. This is called credential stuffing, and it is one of the most common ways accounts are taken over. A different password on every site stops it completely.
Use a password manager
Nobody can remember 100 unique passwords. A password manager stores them encrypted, fills them in for you and warns you about reused or breached passwords. Your phone and browser include one, and there are many dedicated apps. You then only need to remember one strong passphrase.
Turn on two-factor authentication
Two-factor authentication (2FA) asks for a second proof — a code from an app, a security key or a passkey — so a stolen password alone is not enough. Turn it on for your email first, because email is used to reset every other account.
What about passkeys?
Many services now offer passkeys, which replace passwords with a cryptographic key stored on your device and unlocked by your fingerprint, face or PIN. They cannot be phished or reused. Where a service offers passkeys, they are usually the safest choice.
Quick checklist
- At least 12–16 characters, longer for important accounts.
- Unique for every site.
- Stored in a password manager.
- 2FA or passkeys on email, banking and social media.
- Changed immediately if a service tells you it has been breached.