Independent tech news and plain advice
Technologicall

Tech Advice

How to Make a Strong Password You Can Remember

A strong password is long, random and used on only one account. The easiest way to get there is a passphrase of four to seven random words, kept in a password manager.

To make a strong password, make it long, make it random and use it on only one account. The simplest way is a passphrase. That means four to seven random words strung together, like a silly picture only you would think of. Then let a password manager remember it, so you never have to reuse it.

The old rules about one capital letter, one number and one symbol are out. Length is what matters most now.

The Short Answer

  • Length. At least 16 characters, as CISA advises. Longer is stronger.
  • Random. Not your pet's name, birthday, street or favorite team.
  • Unique. One password per account, every time.
  • Stored safely. In a password manager, not a note on your phone or desk.
  • Backed up. With two-factor authentication or a passkey on the accounts that matter most.

Why Length Beats Symbols

Criminals rarely guess passwords by hand. They use computers that try billions of guesses, starting with common passwords and words from leaked lists. Swapping an "a" for "@" or adding "1!" at the end does not fool those tools. They try those swaps first.

Every extra character makes the number of possible passwords much larger. That is why a long passphrase of plain words can be far stronger than a short password stuffed with symbols.

The official guidance agrees. NIST, the US agency that writes the federal standards for digital identity, updated its password rules in August 2025. It says a password used on its own should be at least 15 characters. It also tells websites to allow passwords of at least 64 characters, to stop forcing mixes of letters, numbers and symbols, and to check new passwords against lists of known leaked ones.

How to Make a Passphrase

A passphrase is a string of random words. CISA suggests four to seven unrelated words. Here is how to make a good one.

  • Pick words at random. Open a book to a random page and point, or use the generator in a password manager. Words you choose yourself tend to follow a pattern.
  • Make them unrelated. "Horse Purple Hat Run Bay" is better than a line from a song or a famous quote. Quotes and lyrics are on the guessing lists.
  • Add length, not tricks. A sixth or seventh word does more than a symbol.
  • Spaces are fine. CISA notes you can put spaces between words if a site allows it.
  • Picture it. Make a silly mental image of the words together. It helps you remember the one or two passphrases you have to type by hand.

Do not use the example passphrases you see in articles, including this one. Those end up on guessing lists too.

What Not to Use

  • Your name, your kids' or pets' names, or your birthday.
  • Your street, your town or your team.
  • Keyboard runs like "qwerty" or "123456."
  • A word plus a number, like "Summer2026."
  • The same password on more than one account, even with a small change at the end.

The last one matters most. When a site gets breached, criminals take the leaked emails and passwords and try them on email, banking and shopping sites. This is called credential stuffing. A unique password on every account stops it cold. Breaches happen all the time. We recently covered one that exposed 23.6 million accounts.

Use a Password Manager

Nobody can remember a long, unique password for 100 accounts. A password manager does it for you. It creates strong passwords, saves them and fills them in when you sign in. You only have to remember one passphrase, the one that unlocks the manager.

You have a few kinds to choose from.

  • Built into your device. Apple has the Passwords app, Google has Google Password Manager and Microsoft saves passwords in Edge. They are free and sync across your devices on the same account.
  • Separate apps. Paid and free password managers work across Apple, Android and Windows at once. They are handy if your family mixes devices.

Either way, protect it well. Use a long passphrase for the main password. Turn on two-factor authentication for the manager or the account it syncs with. Lock your phone and computer with a PIN, fingerprint or face unlock.

Are Password Managers Safe?

No tool is perfect, and password managers have been breached before. But for nearly everyone, a password manager is much safer than the other choices. The other choices are reusing passwords, writing them on paper or keeping a list in a notes app. A good manager scrambles your vault so that even the company running it cannot read your passwords without your main passphrase.

The Passwords You Should Fix First

You do not need to change every password tonight. Start with the accounts that can do the most damage.

  • Your main email. It can reset the password on almost every other account.
  • Your Apple, Google or Microsoft account. It holds your photos, backups and saved passwords.
  • Banking and payment apps.
  • Your password manager.
  • Social media, since a hijacked account can be used to scam your friends.

Give each one a new, unique password from your manager. Then turn on two-factor authentication.

How Often to Change Passwords

Less often than you think. NIST says websites should not force you to change passwords on a schedule. Forced changes tend to make people pick weaker passwords with a small tweak, like moving from "Spring1" to "Summer1."

Change a password right away when there is a reason.

  • The site tells you it had a breach.
  • You get a sign in alert you do not recognize.
  • You typed it into a page that turned out to be fake.
  • You shared it with someone who should no longer have it.

If you think you typed a password into a fake page, our guide on how to spot a phishing email explains what to do next.

Go Past Passwords With Passkeys

The strongest password still has one weakness. You can be tricked into typing it on a fake site. Passkeys fix that. A passkey lets you sign in with your face, fingerprint or phone PIN, and it only works on the real site. There is nothing to steal or type.

Many big sites now offer them, including Google, Apple, Microsoft and a growing list of banks and shops. Our guide to passkeys for people who hate passwords shows how to turn one on.

Common Mistakes

  • Adding a symbol and calling it done. Length matters far more.
  • Reusing a good password. Even a great password fails if it leaks from a weak site.
  • Saving passwords in a plain notes app. Anyone with your phone can read them.
  • Skipping two-factor on the password manager. It is the one account that guards all the others.

The Bottom Line

Make passwords long, random and unique. Use a passphrase of four to seven random words for the few you type by hand. Let a password manager handle the rest, and add two-factor authentication or a passkey to the accounts that matter most.

Keep Reading

Follow new breaches in our security news, browse more plain tech advice, or cut down on scam calls with our guide on how to stop spam calls.

Questions Readers Ask

What makes a password strong?

Length, randomness and being used in only one place. CISA, the US cyber defense agency, says to use at least 16 characters and a different password for every account.

Is a passphrase better than a password?

For most people, yes. A string of four to seven unrelated words is long, hard to guess and much easier to remember than a jumble of letters and symbols.

Do I need symbols and numbers in my password?

They help a little, but length helps much more. The current federal password guidance from NIST tells websites not to force rules like one symbol and one number, and to focus on length instead.

How often should I change my passwords?

Only when there is a reason, like a data breach or a sign that someone got in. NIST guidance says websites should not force people to change passwords on a schedule.

Are password managers safe?

For most people they are much safer than reusing passwords or writing them on sticky notes. Protect the manager with a long passphrase and two-factor authentication, since it holds the keys to everything else.

What is the most common password mistake?

Using the same password on more than one site. When one site gets breached, criminals try that email and password everywhere else.

Should I use my browser to save passwords?

The password tools built into Apple, Google and Microsoft accounts are a fine choice for many people. Lock your device with a PIN or face unlock, and protect the account they sync to with two-factor authentication.

Further Reading