Skip to content
KitWren

Everyday guide

How to Create a Strong Password You Can Actually Remember

Updated 27 September 2026 · 3 min read

Most accounts are not hacked by someone guessing your password. They are broken into because the same password was reused on a site that was breached, or because it was short enough for a computer to try every combination. A few simple habits make you far safer than most people online.

Open the free Strong Password Generator

What makes a password strong?

  • Length. Every extra character multiplies the number of possible combinations. Aim for at least 12–16 characters, and more for important accounts.
  • Randomness. Passwords based on names, dates, sports teams or keyboard patterns (qwerty, 123456) are tried first by attackers.
  • Uniqueness. A password used on only one site cannot be used against you when a different site is breached.

Why length beats complexity

“P@ssw0rd!” looks complex, but attackers know every common substitution. A long, random passphrase such as “marble-ocean-tractor-violet” is far harder to crack and much easier to type and remember. Current guidance from security agencies favours long passphrases over short passwords with forced symbols.

Two ways to make a strong password

1. Generate one

The Strong Password Generator creates long random passwords using every character type — ideal for banking, email and admin accounts saved in a password manager. The Password Generator lets you choose the length and which characters to include.

2. Build a passphrase

For the few passwords you must type from memory — your computer login or password manager — choose four or more random, unrelated words. Randomness is the key: “sunny-beach-holiday-fun” is a phrase people might pick; “lantern-pickle-orbit-meadow” is not.

Never reuse passwords

When a website is breached, attackers try the leaked email and password combinations on email, banking and shopping sites. This is called credential stuffing, and it is one of the most common ways accounts are taken over. A different password on every site stops it completely.

Use a password manager

Nobody can remember 100 unique passwords. A password manager stores them encrypted, fills them in for you and warns you about reused or breached passwords. Your phone and browser include one, and there are many dedicated apps. You then only need to remember one strong passphrase.

Turn on two-factor authentication

Two-factor authentication (2FA) asks for a second proof — a code from an app, a security key or a passkey — so a stolen password alone is not enough. Turn it on for your email first, because email is used to reset every other account.

What about passkeys?

Many services now offer passkeys, which replace passwords with a cryptographic key stored on your device and unlocked by your fingerprint, face or PIN. They cannot be phished or reused. Where a service offers passkeys, they are usually the safest choice.

Quick checklist

  • At least 12–16 characters, longer for important accounts.
  • Unique for every site.
  • Stored in a password manager.
  • 2FA or passkeys on email, banking and social media.
  • Changed immediately if a service tells you it has been breached.

Frequently asked questions

How long should a password be?

At least 12 characters, and 16 or more for important accounts. Longer is always stronger.

Are password generators safe?

A generator that runs in your browser, like KitWren’s, creates the password on your device using the browser’s secure random number generator. Nothing is sent or stored.

Should I change my passwords regularly?

Current advice is to change a password when there is a reason — such as a breach — rather than on a fixed schedule. Forced regular changes tend to produce weaker passwords.

Is it safe to save passwords in my browser?

Browser password managers are much safer than reusing passwords. Protect the device and your browser account with a strong password and 2FA.

Tools in this guide