How to create strong, unique passwords
Use length, randomness, password managers and multi-factor authentication to protect accounts without relying on predictable tricks.
A password should be difficult for an attacker to guess and practical for its owner to use safely. Replacing letters with symbols in a familiar word rarely achieves either goal.
Key takeaways
- Use a unique password for every account.
- Prefer long, randomly generated passwords or passphrases.
- Store passwords in a trusted password manager and enable MFA.
Make length do the heavy work
Long passwords provide more possible combinations. Randomly generated values are appropriate for password managers, while a long passphrase can be easier to type when memorisation is necessary.
Avoid predictable patterns
A capital first letter, a year at the end or common substitutions such as @ for a are widely anticipated by guessing tools.
Never reuse an important password
Reuse turns one breached service into a key for other accounts. Every important account should have a distinct credential.
Use a password manager
A reputable manager can generate, store and fill unique passwords, reducing the temptation to create memorable variations of one secret.
Add phishing-resistant protection
Multi-factor authentication adds a barrier when a password is exposed. Security keys and passkeys can offer stronger phishing resistance where supported.
Final check
The practical goal is not a password you can admire; it is a unique secret that remains difficult to guess and easy to manage safely.