Toolpuffin

What Makes a Strong Password?

Updated October 2026

Most advice about passwords is decades old and partly wrong. A strong password is not one that is hard for you to type. It is one that is hard for a computer to guess, and that you use in only one place.

Length matters most

Attackers do not guess passwords by hand. Software tries billions of combinations, starting with common words, names, dates and the usual tricks such as swapping a for @. A short password falls quickly, however odd it looks.

Every extra character multiplies the number of possible passwords. That is why a 16-character password of plain random letters is far stronger than an 8-character one stuffed with symbols.

What 'bits' of strength mean

Password strength is often given in bits. Each bit doubles the number of guesses an attacker needs. For a truly random password the sum is simple: the length times the number of bits per character, which depends on how many different characters could have been chosen.

PasswordPossible charactersStrength
8 random lowercase letters26about 38 bits
8 random letters, numbers and symbolsabout 90about 52 bits
16 random lowercase letters26about 75 bits
16 random letters, numbers and symbolsabout 90about 104 bits

This only holds for random passwords. A password you made up yourself is much weaker than its length suggests, because people choose in predictable ways.

What makes a password weak

  • Words, names, birthdays, football clubs and anything about you that others could know.
  • Keyboard patterns such as qwerty or 123456.
  • A common word with a capital at the start and a number or ! at the end.
  • Reusing the same password, or small variations of it, on several sites.

Reuse is the most dangerous habit. Websites get breached, and the stolen lists of email addresses and passwords are tried automatically on other sites. One leaked password then opens every account that shares it.

The three habits that matter

  1. Use a different password for every account.
  2. Make them long and random. 16 characters or more for anything important.
  3. Turn on two-step verification wherever it is offered, starting with your email.

Nobody can remember dozens of random passwords, and you should not try. A password manager stores them for you and fills them in. You then only need to remember one strong password: the one for the manager itself.

A password you have to remember

For the few passwords you must type from memory, such as the one for your password manager or your computer, a passphrase works well: four or five unrelated words chosen at random, like the output of a word list, not a sentence you thought up. It is long, so it is strong, and it is much easier to remember than random characters.

Do you need to change passwords regularly?

Not on a schedule. Current guidance from the US standards institute NIST advises against forced periodic changes, because they push people towards weak, predictable passwords. Change a password when there is a reason: the site reports a breach, you shared it with someone, or you typed it on a device you do not trust.

More guides