Guide · Updated 2026-10-06
How to Create Strong Passwords
What makes a password hard to crack and how to manage dozens of them safely.
Most account breaches involve weak or reused passwords. Length matters more than clever substitutions.
Rules that work
- Use at least 14 characters, and 20 or more for email and banking.
- Make every password unique, so one breach does not unlock everything.
- Use a random generator instead of patterns such as names and years.
- Turn on two-factor authentication wherever it is offered.
Generate one
The Password Generator creates random passwords with your browser's secure random source. Nothing is stored or sent anywhere. You can test an existing one with the Password Strength Checker.
Store passwords in a reputable password manager so you only remember one strong master passphrase.
Passphrases
A passphrase of four or five random words, such as "copper velvet harbour tiger", is easy to remember and very hard to guess because of its length. It works well as the master password of a password manager. Choose the words randomly instead of picking a quote or lyrics.
What to avoid
- Names, birthdays and pet names, which attackers guess first.
- Keyboard patterns such as qwerty or 123456.
- The same password with a number added for each site.
- Sharing passwords by email or chat.
After a breach
If a service you use reports a breach, change that password at once and change it anywhere else you reused it. Enable two-factor authentication using an authenticator app or a hardware key rather than text messages where you can.
Frequently asked questions
Is a generated password safe to use? Yes. The generator uses your browser's cryptographically secure random source and does not send the password anywhere.
How often should I change passwords? Only when you suspect compromise. Frequent forced changes lead people to choose weaker ones.