Security · 4 min read
How to Choose Strong Passwords (and Why Length Wins)
Password advice is full of myths about symbols and capital letters. The truth is simpler: length and unpredictability are what matter, and the biggest wins come from habits, not from any one clever password.
This guide explains what makes a password strong and how to manage passwords sensibly.
Try it yourself with the related tool.
Generate a strong password →Advertisement
Entropy is what counts
A password's strength comes down to entropy — the number of equally likely possibilities an attacker must search. Entropy grows with both length and the size of the character set, but length has the bigger effect. A long random password is far harder to crack than a short one peppered with symbols.
Randomness beats cleverness
Human-chosen passwords follow predictable patterns — a word, a capital at the start, a number at the end — that attackers exploit. A password generated from a cryptographically secure random source has no such pattern, which is why generated passwords are stronger than memorable ones.
The two habits that matter most
First, never reuse a password across sites: if one site is breached, reuse hands attackers every account that shares it. Second, use a password manager so every login can have a long, unique, random password without you memorizing any of them.
Add a second factor
Even a strong password can be phished or leaked. Turning on two-factor authentication means a stolen password alone is not enough to get in, which dramatically raises the bar for attackers.
