What makes a strong password?
Strong passwords are long, unique, and hard to guess. Randomness beats complexity tricks.
- Aim for 12 to 16+ characters when possible.
- Use a mix of letters, numbers, and symbols if the site allows it.
- Avoid real words, names, or predictable patterns.
Length matters most
Longer passwords are harder to crack. Increasing length is usually more effective than adding extra symbols.
- Use the longest length a site allows.
- Avoid short passwords even if they include symbols.
Use unique passwords
Reusing a password across sites increases your risk. One breach can expose multiple accounts.
- Generate a new password for each account.
- Consider a password manager to store them safely.
Avoid common patterns
Attackers look for predictable substitutions and patterns.
- Skip "P@ssw0rd" style replacements.
- Avoid dates, names, and keyboard walks like "qwerty".
Add extra protection
Where available, turn on two-factor authentication for a second layer of security.
- Use authenticator apps instead of SMS when possible.
- Save backup codes in a secure place.