How to Create Strong Passwords (and What Makes Them Weak)
Learn how attackers crack passwords, what entropy really means, why length beats complexity, and how password managers and 2FA keep you safe.
Last updated · 2026-08-22
How passwords actually get cracked
Few attackers guess passwords at a login form. They steal hashed password databases and crack them offline, or they reuse leaked passwords on other sites — credential stuffing. Cracking tools start with dictionaries of billions of real leaked passwords and apply rules: capitalize the first letter, add a year, swap a for @.
That is why 'Summer2026!' is weak despite having uppercase, lowercase, digits and a symbol: it follows exactly the patterns crackers try first.
Entropy in plain words
Entropy measures unpredictability in bits. A truly random 8-character password from 94 symbols has about 52 bits — crackable with serious hardware. At 16 characters it reaches about 105 bits, which is out of reach. Our password strength checker estimates crack time for any password you type, locally.
Length beats complexity
Each extra random character multiplies the search space. A long random passphrase of five or six words from a large list, such as 'orbit-velvet-cactus-lantern-ripple', is both strong and memorable. Generate one with our mnemonic passphrase tool.
Use a password manager
You cannot remember a unique random password for 100 accounts, and you should not try. A password manager stores them encrypted behind one strong master passphrase. Use our generator to create the passwords and save them directly in the manager.
Turn on two-factor authentication
Even a perfect password can be phished. Authenticator apps (TOTP) or hardware keys stop most account takeovers. Prefer them over SMS codes, which can be intercepted through SIM swapping.
Quick rules
At least 16 random characters or 5 random words; unique per site; stored in a manager; 2FA on email, banking and social accounts; change a password only when there is a reason, such as a breach.