In this article
- What makes a password strong
- Three rules that cover almost everything
- The few passwords you must memorise
- Add two-factor authentication
- Habits to drop
- If a password may have leaked
- How passwords are actually stolen
- What about passkeys?
- A ten-minute plan
- Password styles compared
- Password managers: benefits and trade-offs
- Frequently asked questions
Most account break-ins do not involve anyone guessing a clever password. They happen because a password leaked from one website is tried on others, or because the password was short or common enough to be on an attacker's list. Good password practice is mostly about closing those two doors.
In short: Length beats cleverness. Use a long, unique password for every account, let a password manager remember them, and switch on two-factor authentication.
What makes a password strong
Strength is about how many guesses an attacker would need. Two things drive that number:
- Length. Every extra character multiplies the possibilities. A 16-character password is not twice as strong as an 8-character one; it is astronomically stronger.
- Unpredictability. A password a person invents follows patterns: a word, a capital at the start, a number and symbol at the end. Attackers try those patterns first. Truly random choices have no pattern to exploit.
Summer2026! ticks every box on a typical sign-up form and is weak. A string of 16 random characters, or four unrelated random words, is strong.
Three rules that cover almost everything
1. A different password for every account
This is the most important rule. If you reuse a password and one site is breached, every account sharing it is exposed. Unique passwords contain the damage to one site.
2. Let a generator create them
Humans are poor at randomness. Use the Password Generator or the one built into your password manager, with at least 16 characters.
3. Store them in a password manager
Nobody can memorise a hundred random passwords, and you should not try. A password manager stores them encrypted, fills them in for you, and works across your devices. The ones built into Apple, Google and Microsoft accounts are a reasonable start; dedicated managers add features such as secure sharing.
The few passwords you must memorise
You still need to remember a small number: the master password for your manager, your main email, and your device logins. For these, use a passphrase: several random words, such as four or five picked from a word list or by a generator.
A passphrase like lantern-pickle-orbit-swan is long, easy to type and far easier to remember than xK9$mQ2!vR. The words must be random. A favourite quote or song lyric is not.
Add two-factor authentication
Two-factor authentication (2FA) asks for a second proof, usually a code from an app or a tap on your phone, when you sign in on a new device. With it, a stolen password alone is not enough.
- Turn it on first for email, banking, and your password manager.
- An authenticator app or a hardware security key is stronger than codes sent by text message, though text-message codes are still much better than nothing.
- Save the backup codes somewhere safe when you set it up.
Many services now also offer passkeys, which replace the password with a key stored on your device and unlocked by your fingerprint, face or PIN. They resist phishing, and are worth using where available.
Habits to drop
- Names, birthdays, pets, teams or keyboard patterns such as
qwerty. - Swapping letters for look-alike symbols (
P@ssw0rd). Attack tools try these automatically. - One “strong” password used everywhere.
- Passwords saved in a notes app, spreadsheet or email draft.
- Sharing passwords over email or chat. Use your manager's sharing feature.
If a password may have leaked
Change it on that site immediately, and on any other site where you used the same one. Check whether your email address appears in known breaches with a reputable breach-notification service, and turn on 2FA for the affected account.
How passwords are actually stolen
It helps to know what you are defending against, because each rule in this guide answers one of these.
- Reused passwords from old breaches. When a website is breached, attackers try the leaked email and password pairs on other services automatically. A unique password per account stops this completely.
- Phishing. A message sends you to a convincing copy of a login page. Password managers help because they will not fill your details on the wrong address, and two-factor authentication limits the damage if you are fooled.
- Guessing. Software tries common passwords, dictionary words and predictable patterns such as a capital letter at the start and a year at the end. Length and randomness defeat it.
- Malware and shoulder-surfing. Keeping devices updated and not typing passwords on shared computers covers most of this.
What about passkeys?
Many services now offer passkeys as an alternative to passwords. A passkey is a cryptographic key stored on your phone, computer or password manager and unlocked with your fingerprint, face or device PIN. There is nothing to remember and nothing to type, and because the key only works with the genuine website, it cannot be phished in the usual way. Where a service you rely on offers passkeys, they are worth setting up. Keep a strong password and two-factor authentication on the account as well until you are sure you can sign in from all your devices.
A ten-minute plan
- Change the password on your main email account first. It is the key to resetting all the others.
- Turn on two-factor authentication for email, banking and your password manager.
- Install a password manager and let it replace reused passwords as you log in to each site over the coming weeks.
- Write down recovery codes and keep them somewhere safe at home.
Password styles compared
| Style | Example pattern | Hard to guess? | Easy to remember? |
|---|---|---|---|
| Word plus a number | Summer2024! | No. Patterns like this are tried first | Yes |
| Short random string | 8 mixed characters | Moderately | No |
| Passphrase of random words | four or five unrelated words | Yes | Yes |
| Manager-generated | 20 random characters | Yes | No need: the manager stores it |
Password managers: benefits and trade-offs
- Benefit: a different strong password for every site, filled in for you.
- Benefit: autofill only works on the genuine site, which helps against look-alike phishing pages.
- Trade-off: one master password protects everything, so it must be long, unique and backed by two-factor authentication.
- Trade-off: you need a recovery plan. Store the recovery code somewhere safe and offline.
Need one now? The Password Generator creates passwords on your own device and never sends them anywhere.
Frequently asked questions
How long should a password be?
Aim for at least 16 characters for random passwords, or four or more random words for a passphrase. Longer is better for the few passwords that protect everything else, such as your email and password manager.
Do I need to change my passwords regularly?
Current guidance, including from the US National Institute of Standards and Technology, is to change a password when there is reason to think it has been exposed, not on a fixed schedule. Forced regular changes tend to produce weaker, predictable passwords.
Are password managers safe?
Reputable ones encrypt your vault with your master password so that even the provider cannot read it. No system is risk-free, but for most people a password manager is far safer than reusing passwords or keeping them in a document.
