How to Create Strong Passwords (and Actually Remember Them)
Weak and reused passwords are still one of the most common ways accounts get hacked. When a website suffers a data breach, attackers take the leaked email and password combinations and try them on other popular sites. If you use the same password everywhere, one breach can unlock your email, social media and even your bank.
The good news is that protecting yourself is not complicated. This guide explains what makes a password strong, how to create ones you can remember, and why a password manager makes the whole process easy.
What makes a password strong?
Password strength comes down to how hard it is for a computer to guess. Attackers use software that tries billions of combinations and common patterns. A strong password has three qualities:
- Length: this is the most important factor. Aim for at least 12–16 characters. Every extra character makes a password dramatically harder to crack.
- Unpredictability: avoid names, birthdays, keyboard patterns like
qwerty, and common words with simple substitutions likeP@ssw0rd. - Uniqueness: every account should have its own password.
Common password mistakes
| Mistake | Why it is risky |
|---|---|
| Using your name or birth date | Easy to find on social media |
| Reusing one password | One breach exposes every account |
| Short passwords (8 characters or fewer) | Can be cracked quickly by modern hardware |
| Adding "123" or "!" at the end | Attack tools try these patterns first |
| Saving passwords in a notes app or photo | Anyone with your phone can read them |
Method 1: Use a passphrase
A passphrase is a string of several random words. It is long, which makes it strong, but it is also much easier to remember than a jumble of symbols.
For example, copper-violin-harbor-pencil is 28 characters long and far stronger than something like Tr0ub@dor. The key is that the words must be random and unrelated. A famous quote or song line is not random, and attackers include those in their word lists.
- Pick four to six unrelated words. Using dice with a word list, or a password manager's generator, gives the best randomness.
- Separate them with hyphens, spaces or a character you like.
- If a website insists on numbers or capitals, add them in a way you will remember, such as
Copper-violin-harbor-pencil-7.
Method 2: Use a password manager (recommended)
Nobody can remember 50 unique, strong passwords. A password manager solves this. It is a secure, encrypted vault that stores all your passwords, generates strong new ones, and fills them in automatically on websites and apps.
You only need to remember one strong master password, which should be a good passphrase. Everything else is handled for you.
Options to consider
- Built-in managers: Google Password Manager (Chrome and Android) and Apple Passwords (iPhone, iPad, Mac) are free and already on your device.
- Dedicated managers: well-known options include Bitwarden, 1Password and Proton Pass. These work across different browsers and operating systems.
Getting started
- Choose a manager and create a strong master passphrase.
- Turn on two-factor authentication for the manager itself.
- Start with your most important accounts: email, banking and social media. Change each to a new generated password.
- Update other accounts gradually as you log into them.
What about passkeys?
Many sites now support passkeys, a newer way to sign in using your phone's fingerprint, face unlock or screen lock instead of a password. Passkeys cannot be phished or reused, which makes them very secure. Whenever a service you use offers passkeys, it is worth turning them on.
Check whether your passwords have leaked
Most password managers include a security check that warns you about weak, reused or breached passwords. You can also enter your email address at Have I Been Pwned, a well-known free service, to see whether it has appeared in known data breaches. If it has, change the password for that account and anywhere else you used it.
Add a second layer of protection
Even a strong password can be stolen by a fake login page. That is why you should also turn on two-factor authentication (2FA) for important accounts. With 2FA, a stolen password alone is not enough to get in. Read our guide on how to set up two-factor authentication for step-by-step instructions.
Frequently asked questions
How often should I change my passwords?
Current security guidance says you do not need to change strong, unique passwords on a schedule. Change a password immediately if a service reports a breach or you suspect someone else knows it.
Is it safe to store passwords in a password manager?
Reputable password managers encrypt your data so that only your master password can unlock it. Used with a strong master password and 2FA, they are far safer than reusing passwords or writing them down.


