The most common passwords in the world are still 123456, password and qwerty. Meanwhile AI-powered cracking tools get faster every year, and stolen credentials circulate in massive breach databases. The good news: following a few simple rules puts you ahead of 99% of attacks. No computer-science degree required.
Rule 1 — Go long: 16 characters minimum
📏 Length beats complexity
Current NIST guidance requires at least 15 characters when a password is your only login factor, and recommends allowing up to 64. A random 16-character password is astronomically harder to brute-force than a clever 8-character one. When in doubt, add length — not another exclamation mark.
Rule 2 — Never reuse a password
🚫 One breach shouldn't unlock everything
Attackers take leaked passwords and automatically try them on banking, email and shopping sites ("credential stuffing"). Reusing even a strong password across accounts defeats its strength entirely. Every account gets its own password — no exceptions for email and banking especially.
Rule 3 — Use a password manager
🗝️ Remember one password, not one hundred
Nobody can memorise 80 unique 16-character passwords — and you shouldn't try. A reputable manager (Bitwarden is free and open-source; 1Password is a polished paid option) generates, stores and auto-fills strong passwords for you. You only memorise one strong master password.
Rule 4 — For memorable secrets, use random passphrases
🐴 battery-horse-staple-correct
For the few passwords you must type from memory (your master password, your laptop login), use 4–6 genuinely random unrelated words. The words must be random — not a quote, lyric or sentence about your life. Randomness is the strength; meaning is the weakness.
Rule 5 — Turn on 2FA everywhere
📱 A second lock on the door
Two-factor authentication means a leaked password alone isn't enough. Prefer an authenticator app over SMS codes where offered, and enable 2FA on email first — your inbox is the master key to password resets everywhere.
Rule 6 — Don't "retire" passwords on a schedule
📅 Change on suspicion, not on schedule
Forced 90-day changes were retired by modern guidance: they push people toward weaker, predictable variations (Summer2026! → Autumn2026!). Change a password when it's weak, reused, shared, phished, or appears in a breach — not because the calendar says so.
Rule 7 — Check breaches and avoid the obvious
🔍 Assume attackers know the classics
Skip pet names, birthdays, keyboard walks (qwerty, 1q2w3e) and "clever" substitutions (P@ssw0rd — cracking dictionaries try every permutation). Periodically check whether your email appears in known breaches and rotate anything exposed.
📥 Free download: Password Security Checklist
A one-page checklist of all 7 rules — print it, stick it near your desk, share it with family.
Try it now
Don't just read about strong passwords — make one. Our free Password Generator creates cryptographically random passwords with a live strength meter, entirely in your browser. Nothing is stored or sent anywhere.