Guide
How to make a strong password without making it impossible to remember
A practical guide to the factors that actually make passwords strong, why length beats complexity, and the case for a password manager.
Length is the most important factor
Every additional character multiplies the possible combinations exponentially. A 16-character password of random words is far harder to crack than an 8-character password with uppercase, symbols, and numbers. The practical implication: prioritise length over complexity if you have to choose.
Personal information is the main vulnerability
Birthdays, pet names, children's names, memorable addresses, and favourite teams are the first things tried in a targeted attack. They are also present in data breaches, social media, and public records. A password that is not based on anything about you is categorically safer than one that is, regardless of length.
A password manager solves the remembering problem
The practical barrier to strong, unique passwords for every account is that human memory cannot hold them. A password manager generates, stores, and fills strong unique passwords, requiring you to remember only one strong master password. This is the recommended approach for people who take account security seriously.