Skip to content
M2TOOLKIT

Security guide

How to Create a Strong Password You Don't Have to Remember

What actually makes a password strong, why length beats symbols, when to use a passphrase, and the simple system that keeps every account safe.

By M2Toolkit Editorial TeamPublished 6 min read

Quick answer

Use a random password of at least 16 characters, a different one for every account, saved in a password manager. For the few passwords you must type or remember — like the manager itself — use a passphrase of five or six random words. Turn on two-factor authentication wherever you can.

Most password advice focuses on symbols and capital letters, but attackers don't care much about those. What makes a password strong is that it's long, random and used in only one place. Here's why, and a simple system that keeps every account safe without memorising dozens of strings.

How passwords actually get cracked

  • Credential stuffing: passwords leaked from one site are tried on others. Reuse is the single biggest risk.
  • Dictionary and pattern attacks: attackers try common passwords, words, names, dates and patterns like “Summer2024!” first — billions per second when they have a stolen password database.
  • Phishing: no password is strong enough if you type it into a fake login page. Password managers help here too: they won't autofill on the wrong website.

Why length beats complexity

Strength comes from the number of possible combinations, measured in bits of entropy. Each extra character multiplies the possibilities, so length adds strength much faster than swapping letters for symbols.

PasswordTypeApprox. strength
P@ssw0rd2024!Predictable patternVery weak — on every attacker's list
k8#Qz!Random, 6 charactersWeak (~39 bits)
x7$Kp2!qLm9#Vw4zRandom, 16 charactersVery strong (~103 bits)
maple-ticket-orbit-quiet-crane-velvet6 random wordsStrong (~61 bits) and memorable
Try the free Password Strength CheckerSee how a password holds up against common attacks — checked on your device only.

A simple system that works

  1. 1
    Pick a password manager. The one built into your phone or browser is fine; dedicated apps add sharing and cross-platform sync.
  2. 2
    Protect it with a long passphrase — five or six random words you can type easily.
  3. 3
    Generate a unique random password for every account and let the manager remember it.
  4. 4
    Turn on two-factor authentication, starting with email, banking and your password manager.
  5. 5
    Change passwords only when there's a reason — a breach, a shared account or a suspicious login. Forced regular changes tend to make passwords weaker.
Try the free Password GeneratorRandom passwords from your browser's secure generator, never stored or sent.

When to use a passphrase

Passphrases are best for passwords you type by hand: your password manager, your computer login, a TV streaming account. The words must be chosen randomly — a favourite quote or song lyric is far weaker than it looks.

Try the free Passphrase GeneratorRandom words from a list of over a thousand, picked with secure randomness.

Frequently asked questions

How long should a password be?

At least 12 characters for random passwords, 16 or more for important accounts. For passphrases, five or six random words.

Are password managers safe?

Reputable managers encrypt your vault with your master password before it leaves your device. They're far safer than reusing passwords, which is what most people do without one.

Should I add symbols?

They help a little, and some sites require them, but length and randomness matter much more.

About this guide

The people who build M2Toolkit's tools write these guides. Every formula and example in an article is checked against the matching tool, and articles are reviewed when the tool changes.

Tools mentioned in this guide