How passwords are actually stolen
Choosing a defence requires knowing the attack. Accounts are most often compromised not because a password was guessed, but because some service you registered with was breached and that password was then tried elsewhere โ credential stuffing. However complex a password is, reusing it means one breach opens everything.
Length over complexity
Mixing in symbols is an old convention; length is the far stronger defence. Long and memorable generally beats short and complex. One caveat: combining unrelated words is good, but using a well-known phrase or lyric verbatim is not, since those already sit in attack dictionaries.
- Prioritise length over complexity
- Combine several unrelated words
- Avoid famous phrases, lyrics and quotations
- Never use names, birthdays or phone numbers
Breaking reuse in practice
Using a different password everywhere is correct advice, but memorising dozens is impossible โ which is why a password manager is the realistic answer. You remember one strong master password and the software generates and stores the rest. If you will not use one, at least make your important accounts entirely distinct. Email matters most, since every other service's reset link arrives there.
Two-factor changes the game
Even if a password leaks, a second factor blocks the login โ which makes two-factor authentication far more valuable than added complexity. Methods differ in strength: SMS is vulnerable to number takeover and weaker than an authenticator app or hardware key. Even so, SMS is vastly better than nothing.
- Hardware security key: strongest
- Authenticator app: strong and free, recommended
- SMS: weaker, but better than none
- Apply it to your email account first
On changing passwords regularly
Periodic change used to be standard advice. Forcing frequent changes was found to make people adopt predictable patterns โ incrementing a trailing number โ so recent security guidance has moved away from recommending scheduled changes. Changing immediately on news of a breach is what matters.
About the tools here
The password generator and strength meter on this site run entirely in your browser; nothing you type or generate is transmitted or recorded. As a general habit, though, avoid typing passwords you actually use into arbitrary websites.
๐ Search the web for this
Each button runs this keyword on that search engine
๐ More in this category