Security guide · 8 min read

How to create strong, unique passwords

Use length, randomness, password managers and multi-factor authentication to protect accounts without relying on predictable tricks.

A password should be difficult for an attacker to guess and practical for its owner to use safely. Replacing letters with symbols in a familiar word rarely achieves either goal.

Key takeaways

  • Use a unique password for every account.
  • Prefer long, randomly generated passwords or passphrases.
  • Store passwords in a trusted password manager and enable MFA.

Make length do the heavy work

Long passwords provide more possible combinations. Randomly generated values are appropriate for password managers, while a long passphrase can be easier to type when memorisation is necessary.

Avoid predictable patterns

A capital first letter, a year at the end or common substitutions such as @ for a are widely anticipated by guessing tools.

Never reuse an important password

Reuse turns one breached service into a key for other accounts. Every important account should have a distinct credential.

Use a password manager

A reputable manager can generate, store and fill unique passwords, reducing the temptation to create memorable variations of one secret.

Add phishing-resistant protection

Multi-factor authentication adds a barrier when a password is exposed. Security keys and passkeys can offer stronger phishing resistance where supported.

Final check

The practical goal is not a password you can admire; it is a unique secret that remains difficult to guess and easy to manage safely.

Sources and further reading

Try it now

Related Security tools

All tools →

Try “make image smaller”, “jpg into pdf”, “pretty json” or “count my words”.