Everything you need to know about creating strong, secure passwords
A strong password should be at least 12-16 characters long and include a mix of:
Avoid:
A secure password has three key characteristics:
The longer and more random a password is, the harder it is to crack. Using uppercase, lowercase, numbers, and symbols increases the possible combinations exponentially.
For example, a 12-character password using all character types has approximately 540 quadrillion possible combinations, which would take centuries to crack with current technology.
Your password should be at least 12 characters long, though 16 or more characters is recommended for sensitive accounts like email, banking, or work systems.
Here's why length matters:
Yes! Special characters like !@#$%^&*() significantly increase password strength by expanding the character set from 62 (letters + numbers) to 94+ possible characters.
This makes brute-force attacks exponentially harder. However, length is more important than complexity:
Best practice: Use both length AND complexity for maximum security.
No, absolutely not! Using the same password across different accounts is one of the most dangerous security mistakes you can make.
Why it's dangerous:
If one service is breached and your password is leaked, attackers will try that password on other popular services like Gmail, Facebook, Amazon, and banking sites. This attack is called credential stuffing and it's extremely common.
Real-world example: In 2023, over 24 billion username/password combinations were leaked from various breaches. Attackers systematically test these credentials on major services.
A password manager is software that securely stores all your passwords in an encrypted vault, protected by one master password.
Key features:
Should you use one? YES! It's the only practical way to use unique, strong passwords for every account.
💡 Pro Tip: Start with Bitwarden's free tier to test password managers. Once you're comfortable, upgrade to 1Password for the best user experience, or stick with Bitwarden Premium for unbeatable value at $10/year.
Popular options:
Writing down passwords on paper and keeping them in a physically secure location (like a locked safe at home) is actually more secure than reusing weak passwords you can remember.
Pros of writing passwords down:
Cons:
Modern security guidance: You only need to change passwords if there's evidence of a breach or compromise.
Why frequent password changes are no longer recommended:
When you SHOULD change a password:
Modern browsers like Chrome, Firefox, and Safari encrypt saved passwords, but browser password managers are less secure than dedicated password managers.
Limitations of browser password storage:
If you use browser password storage:
Recommendation: For best security, use a dedicated password manager like Bitwarden or 1Password instead.
Yes, reputable password generators are safe when they generate passwords locally in your browser without sending data to a server.
TulBench's password generator:
How to verify: Open your browser's developer tools (F12) and check the Network tab - you'll see no requests are made when generating passwords.
A passphrase is a sequence of random words (like correct-horse-battery-staple) that's easier to remember than a random character password but still secure.
Example passphrases:
Planet-Tango-Midnight-Coffee-71Envelope.Giraffe.Thunder.WalnutJazz+Kitchen+Marble+OxygenPassphrase pros:
Passphrase cons:
Verdict: Passphrases work well when you need to memorize a password (like your password manager master password). For everything else, use random passwords stored in a password manager.
Hackers use several methods to crack passwords:
A truly random 12-character password using letters, numbers, and symbols has 95^12 possible combinations (approximately 540 quadrillion combinations).
Time to crack by brute force:
However... if the password uses dictionary words or patterns, it can be cracked much faster (minutes to hours) using dictionary attacks.
Examples:
aB3$xQ9@mK2! - Truly random: ~400 years to crack ✅Password123! - Dictionary word: Cracked in seconds ❌TomSmith1985 - Personal info: Cracked in seconds ❌Two-factor authentication (2FA) adds a second verification step beyond your password, such as:
Why 2FA matters: Even if someone steals your password (through phishing, data breach, or keylogger), they can't access your account without the second factor.
2FA strength ranking:
Top 15 password mistakes:
Use our free password generator to create secure, random passwords in seconds
Generate Password NowSecure your internet connection and hide your IP address with a trusted VPN service
Learn About VPNs