Security guide
How to Create a Strong Password You Don't Have to Remember
What actually makes a password strong, why length beats symbols, when to use a passphrase, and the simple system that keeps every account safe.
By M2Toolkit Editorial TeamPublished 6 min read
Quick answer
Use a random password of at least 16 characters, a different one for every account, saved in a password manager. For the few passwords you must type or remember — like the manager itself — use a passphrase of five or six random words. Turn on two-factor authentication wherever you can.
Most password advice focuses on symbols and capital letters, but attackers don't care much about those. What makes a password strong is that it's long, random and used in only one place. Here's why, and a simple system that keeps every account safe without memorising dozens of strings.
How passwords actually get cracked
- Credential stuffing: passwords leaked from one site are tried on others. Reuse is the single biggest risk.
- Dictionary and pattern attacks: attackers try common passwords, words, names, dates and patterns like “Summer2024!” first — billions per second when they have a stolen password database.
- Phishing: no password is strong enough if you type it into a fake login page. Password managers help here too: they won't autofill on the wrong website.
Why length beats complexity
Strength comes from the number of possible combinations, measured in bits of entropy. Each extra character multiplies the possibilities, so length adds strength much faster than swapping letters for symbols.
| Password | Type | Approx. strength |
|---|---|---|
| P@ssw0rd2024! | Predictable pattern | Very weak — on every attacker's list |
| k8#Qz! | Random, 6 characters | Weak (~39 bits) |
| x7$Kp2!qLm9#Vw4z | Random, 16 characters | Very strong (~103 bits) |
| maple-ticket-orbit-quiet-crane-velvet | 6 random words | Strong (~61 bits) and memorable |
A simple system that works
- 1Pick a password manager. The one built into your phone or browser is fine; dedicated apps add sharing and cross-platform sync.
- 2Protect it with a long passphrase — five or six random words you can type easily.
- 3Generate a unique random password for every account and let the manager remember it.
- 4Turn on two-factor authentication, starting with email, banking and your password manager.
- 5Change passwords only when there's a reason — a breach, a shared account or a suspicious login. Forced regular changes tend to make passwords weaker.
When to use a passphrase
Passphrases are best for passwords you type by hand: your password manager, your computer login, a TV streaming account. The words must be chosen randomly — a favourite quote or song lyric is far weaker than it looks.
Try the free Passphrase GeneratorRandom words from a list of over a thousand, picked with secure randomness.Frequently asked questions
How long should a password be?
At least 12 characters for random passwords, 16 or more for important accounts. For passphrases, five or six random words.
Are password managers safe?
Reputable managers encrypt your vault with your master password before it leaves your device. They're far safer than reusing passwords, which is what most people do without one.
Should I add symbols?
They help a little, and some sites require them, but length and randomness matter much more.