What actually makes a password strong?
Length, randomness and uniqueness solve different problems. Here is how to use all three.
Start with the problem you’re solving
An attacker may try common passwords online, or guess against stolen password hashes offline. Online services can limit attempts; stolen hashes can often be attacked much faster. A password that resists guessing still fails if you reuse it on a breached service. Choose a new credential for every account.
Length creates room for randomness
Adding characters to a randomly generated password increases the number of possible values. Replacing an “a” with “@” in a familiar word offers much less help because guessing tools already try substitutions. Use the longest random password that is practical for your service, with 16 or more characters as a useful starting point.
Randomness is the crucial ingredient
A birthday, keyboard pattern, or favorite lyric can be long and still predictable. PasswordCraft uses the browser’s cryptographic random-number generator. For selected character types, it rejects candidates that omit a type, rather than inserting mandatory characters in a way that biases outcomes. The strength checker can flag patterns, but it cannot certify a password.
Let a password manager do the remembering
A manager can generate and store separate long credentials for your accounts. Protect the manager with a strong unique master credential and available multifactor authentication. Check its recovery instructions before you need them. Avoid keeping secrets in screenshots, shared notes, or email drafts.
When should you change a password?
Change it when it has been exposed, reused, shared unintentionally, or used on a compromised device. Arbitrary frequent changes can encourage predictable edits. Follow your organization’s requirements and the service’s security guidance.
Try this today
Start with your primary email account: make its password unique, enable a passkey or multifactor authentication, and review recovery options. Your email often resets access to other services, so protecting it has a broad benefit.
Further reading
NIST digital identity guidelines ↗
OWASP authentication guidance ↗
Try the password generator or passphrase generator.