How to make a strong password
A strong password is one that software cannot guess in a realistic amount of time. That depends on two things: how long it is, and how random. Clever tricks such as swapping letters for symbols add very little, while a few extra random characters or words add a great deal.
Try it now: Password Generator, Hash Generator.
Why tricks do not help
Attackers do not type guesses. They use software that tries billions of candidates, starting with common words, names, dates, keyboard patterns and the usual substitutions such as an @ for an a. A password like P@ssw0rd! feels complicated but is one of the first things they try. A truly random password has no pattern to exploit.
Measuring strength in bits
Strength is measured as entropy in bits. For a random password, the entropy is the length multiplied by log2 of the number of characters it could have used from. Each extra bit doubles the number of guesses needed, so 10 more bits makes a password about a thousand times harder to guess. This table uses the same ratings as the password generator:
| Password | Entropy | Rating |
|---|---|---|
| 8 lowercase letters | 37.6 bits | Weak |
| 8 random characters from all 94 | 52.4 bits | Fair |
| 12 random characters from all 94 | 78.7 bits | Strong |
| 16 random characters from all 94 | 104.9 bits | Very strong |
| 4 random words | 51.7 bits | Fair |
| 5 random words | 64.6 bits | Strong |
| 6 random words | 77.5 bits | Strong |
| 7 random words | 90.5 bits | Very strong |
Length beats complexity
Making a password longer helps more than making it fussier. Take a 12-character password and allow symbols as well as letters and digits, and the number of possible characters rises from 62 to 94, which adds about 7 bits. Add four more random characters instead and you gain about 26 bits, which is tens of millions of times more guesses. So if a site lets you, choose a long password and do not worry about every symbol.
Passphrases: strong and easier to remember
A passphrase is several random words, such as those picked from a list of 7,776 words. Each word adds about 12.9 bits, so five or six words are already strong, and words are much easier to type and remember than 12 random symbols. The words must be chosen randomly. A quote or a phrase you made up is not random and is far weaker.
Use a different password for every account
When a website is breached, the stolen passwords are tried on other sites. A strong password reused in two places is only as safe as the weaker site. Keep one unique password per account and let a password manager remember them. Then you only need to memorise one long passphrase for the manager itself, and you should turn on two-step verification wherever it is offered.
How sites should store your password
A well-run site never keeps your password, only a slow, salted hash made with an algorithm such as bcrypt, scrypt or Argon2. A fast hash like plain SHA-256, which a hash generator will show you, is quick to compute, and that makes it quick for an attacker to test guesses against a stolen copy. You cannot control how a site stores your password, which is one more reason to make yours long and random.