September 13, 2026 · 6 min read

How to create a strong password (and actually remember it)

Most advice about passwords focuses on the wrong variable. Sites tell you to mix uppercase, numbers, and symbols, so people respond with Password1! — which technically satisfies every rule and is still one of the first guesses any cracking tool tries. The character classes you use matter far less than how long the password is and how it was chosen.

Length does almost all the work

Every password has a keyspace: the total number of possible passwords of that length and character set. A lowercase-only password 8 characters long has 26⁸ possible combinations — about 209 billion. That sounds like a lot until you know that consumer GPU hardware can test billions of guesses per second against a leaked, unsalted hash. Add one more character and the keyspace multiplies by 26; add a digit and symbol set and it multiplies again. A random 16-character password with all four character classes has a keyspace so large that brute force stops being a realistic attack at all — you run into the age of the universe before you run into the password. That's the entire reason our password generator defaults to 16 characters instead of 8.

The substitutions that don't fool anyone

Swapping a for @ or o for 0 feels clever, but every password-cracking wordlist has included these substitutions for over a decade. Tools like Hashcat run "mangling rules" over dictionary words automatically — trying password, p@ssword, P@ssw0rd!, and hundreds of other variants of every word in the list without a human doing it by hand. If a password started as a real word, a name, a pet, or a keyboard pattern like qwerty123, a mangled dictionary attack usually finds it in seconds, no matter how it's dressed up. The only passwords that resist this are ones that were never a word to begin with — which is what a true random generator produces and a human trying to be clever rarely does.

Passphrases: the readable exception

There's one way to get a memorable password that's still genuinely random: pick several words independently at random, rather than composing a sentence you thought up yourself. A phrase you construct — even something unusual — draws on the same limited vocabulary and grammar patterns attackers already model. Four or more words pulled independently from a large word list, like correct-horse-battery-staple-style passphrases, don't have that structure to exploit, and the resulting entropy is comparable to a long random character string while being far easier to type and recall.

The bigger threat isn't a weak password at all

In practice, most account takeovers today don't involve cracking anything. They involve credential stuffing: attackers take email/password pairs from one breached site and try them against every other major site, because so many people reuse the same password everywhere. A perfectly strong password does nothing to stop this if it's the same strong password on ten different accounts. The fix is a unique password per site — which is only realistic with a password manager to store them, so you only have to remember one master passphrase instead of a hundred account passwords.

A short checklist

You can put all of this into practice directly: generate a strong password with the password generator, or check one you already use with the strength checker.