How to Create a Strong Password (and Why Length Beats Complexity)
Learn what makes a password strong, how long it should be, and generate a random password in your browser with the free password generator.
Most account break-ins do not involve clever hacking. They use passwords that are short, common or reused from another site. A strong password is the cheapest and most effective protection you can have, and it takes seconds to make with the free Password Generator.
Quick answer
Choose a length of at least 14 to 16 characters, select the character types you want and press generate. The password is created in your browser with a secure random generator and is never sent anywhere. Store it in a password manager.
What makes a password strong
- Length. Every extra character multiplies the number of possibilities. Length matters more than special symbols.
- Randomness. A password chosen by a random generator cannot be guessed from your name, birthday or favourite team.
- Uniqueness. A different password for every important account, so that one leak does not open everything.
How long should it be?
- 12 characters is a reasonable minimum for most accounts.
- 16 or more is a good target for email, banking and your password manager.
- 20 or more is comfortable when a password manager types it for you.
The generator allows lengths from 8 to 64.
What to avoid
- Names, birthdays, phone numbers and pet names
- Words from a dictionary with a number at the end, such as
Rahim2024 - Keyboard patterns such as
qwertyand12345678 - The same password on several sites
- Slight changes to an old password, such as adding
1
How to use the generator, step by step
- Open the Password Generator.
- Choose the length.
- Choose which characters to include: upper case, lower case, numbers, symbols.
- Press generate.
- Copy the password and save it in your password manager.
The tool leaves out look-alike characters such as the letter O and the digit 0, so that the password is easy to read when you must type it.
Passwords you must remember
A random string is hard to memorise, and you should not have to. Use a password manager for your accounts. For the few passwords you must remember, such as the manager's master password and your phone, use a passphrase: four or five unrelated words, such as green-river-lamp-bicycle. It is long, easy to recall and hard to guess.
Other habits that protect you
- Turn on two-step verification for email, banking and social accounts.
- Never share a one-time code with anyone, even someone claiming to be support.
- Check for breaches of your email address on a reputable service and change affected passwords.
- Do not type passwords on shared computers you do not trust.
- Lock your phone with a PIN or biometrics.
Related tools
- Protect PDF with a Password to lock private files.
- Hash Generator to verify that a file has not changed.
- UUID Generator for random unique identifiers.
How attackers actually guess passwords
Understanding the methods explains the advice:
- Dictionary attacks try common words and names, including variants such as
P@ssw0rd. - Credential stuffing takes leaked passwords from one site and tries them on others.
- Brute force tries every combination, which is only feasible for short passwords.
- Phishing tricks you into typing your password on a fake page.
- Shoulder surfing and malware capture what you type.
Long, random, unique passwords defeat the first three, and two-step verification limits the damage of the others.
Setting up a password manager
- Choose a reputable manager with good reviews and regular updates.
- Create a strong master passphrase of several unrelated words.
- Turn on two-step verification for the manager itself.
- Import or add your accounts, starting with email and banking.
- Replace weak and repeated passwords with generated ones, one account at a time.
- Keep recovery codes in a safe place.
Which accounts to secure first
| Priority | Account | Why |
|---|---|---|
| 1 | Primary email | Used to reset every other password |
| 2 | Banking, bKash, Nagad and payment apps | Direct financial loss |
| 3 | Social media | Impersonation and scams |
| 4 | Cloud storage | Private files and photos |
| 5 | Shopping and subscriptions | Stored cards and addresses |
Signs your account may be compromised
- Login alerts from places or devices you do not recognise.
- Messages you did not send to your contacts.
- Password reset emails you did not request.
- Unknown purchases or changed account details.
If you see these, change the password immediately from a trusted device, sign out of other sessions and turn on two-step verification.
Quick checklist
- Use a password manager.
- Generate long random passwords.
- Make each one unique.
- Turn on two-step verification.
A worked example: cleaning up your accounts in one weekend
Zara realises that she uses the same password on her email, Facebook and shopping sites. On Saturday she installs a password manager and sets a passphrase of five unrelated words as the master password. She changes her email password first, then banking and mobile wallet apps, using generated 16-character passwords, and turns on two-step verification for each. On Sunday she works through social media and shopping accounts, deleting accounts she no longer uses. By the end of the weekend, a leak from one old site can no longer unlock her other accounts.
Beware of scams
- Never share a verification code, even with someone who says they are from support.
- Check the address bar before typing a password.
- Be careful with links in messages, especially urgent ones about your account.
- Use official apps and sites, typed or bookmarked by you.
Frequently asked questions
Is the password stored anywhere? No. It is created in your browser and is never sent anywhere.
How long should my password be? At least 12 characters; 16 or more is better for important accounts.
Are symbols required? Not necessarily. Length gives most of the strength.
Why are some characters left out? Look-alike characters such as O and 0 are removed so that the password is easy to read.
Is it free? Yes.
Is it safe to use a password manager? Reputable managers encrypt your data, and a single strong master password is safer than many weak ones.
How often should I change passwords? Change them when there is a breach or a suspicion, rather than on a fixed schedule, and always use unique ones.
Is a pattern lock or fingerprint enough? They help on a phone, but important accounts also need strong passwords and two-step verification.
Should I write passwords on paper? A paper kept in a safe place is better than reusing weak passwords, but a manager is better still.
What about biometric login? It is convenient, but keep a strong password or PIN as a backup.
Next step
Open the Password Generator below and replace one weak password today, starting with your email.
