How to create a strong password

By M Alamgir Saeed · Updated

For years we were told to mix capitals, numbers and symbols and change our passwords every few months. Security guidance has changed: length matters far more than odd characters, and forced changes often make passwords weaker. Here is what current advice from the US National Institute of Standards and Technology (NIST) says, in plain English.

Length beats complexity

Every extra character multiplies the number of guesses an attacker needs. That is why NIST's digital identity guidelines (SP 800-63B) now say that a password used on its own, without a second factor, should be at least 15 characters long, and that websites should allow passwords of at least 64 characters.

Complexity rules such as "one capital, one number, one symbol" are no longer required by that guidance. They tend to produce predictable patterns, like a capital at the start and "1!" at the end, which attackers already try first.

Use a passphrase or a generated password

There are two good ways to get a long password. The first is a passphrase: four or more random, unrelated words, such as "copper lantern meadow orbit". It is long and surprisingly easy to remember. Pick the words at random rather than using a quote, a song lyric or a phrase about yourself.

The second is a random password from a generator, which is ideal when a password manager remembers it for you. The Password Generator on this site creates passwords with your browser's cryptographic random number generator, and nothing is sent or stored.

Never reuse a password

Reuse is the biggest real-world risk. When one website is breached, attackers try the leaked email and password on email, banking and shopping sites. A unique password for every account stops one breach from spreading. NIST also advises services to check new passwords against lists of passwords known to be compromised.

Change passwords when there is a reason, not on a schedule

The same guidance says services should not force people to change passwords periodically. Forced changes lead to small, guessable edits such as "Summer2025" becoming "Autumn2025". Change a password when there is evidence it may be compromised, for example after a breach notice, if you shared it, or if you typed it on a device you do not trust.

A simple checklist

  • At least 15 characters for any important account.
  • A random passphrase or a generated password, never personal details.
  • A different password for every account.
  • A password manager to store them.
  • Two-factor authentication on email, banking and social accounts.

Try the free Password Generator

Frequently asked questions

How long should a password be?

At least 15 characters if it is the only thing protecting the account. Longer is better, and a passphrase of four or more random words reaches that easily.

Do I still need symbols and numbers?

Not according to current NIST guidance, although some websites still require them. Length and uniqueness matter much more.

Is a password generator safe to use online?

This one creates passwords in your browser with a cryptographic random number generator; nothing is sent to a server or saved.

Sources