Password Security — Best Practices
Learn how to create and manage secure passwords. Generate strong, random passwords instantly with our Password Generator.
Strong Password Examples
Good passwords are long, random, and contain a mix of character types.
7x!Kp#9mQ@2zL$5rVery Strong
16 characters, mixed case + symbols + digits
J8&vP4*nW1!cR7%tF3Very Strong
18 characters, high complexity
correct-horse-battery-stapleStrong
28 characters, word-based (XKCD method)
Tr0ub4dor&3Moderate
11 characters, leetspeak variant
Weak Password Examples (Avoid)
password123Extremely common, dictionary word + digits
Time to crack: < 1 second
12345678Sequential numbers, most common password pattern
Time to crack: < 1 second
qwertyKeyboard pattern, easily guessable
Time to crack: < 1 second
passwordMost common password of all time
Time to crack: < 1 second
admin2024Common base word + predictable year
Time to crack: < 1 second
letmeinCommon phrase, dictionary word
Time to crack: < 1 second
P@ssw0rdCommon leetspeak substitution, well-known pattern
Time to crack: < 2 seconds
John1985Name + birth year, easily guessed from social data
Time to crack: < 10 seconds
Password Strength by Length
| Length | Entropy (bits) | Time to Crack | Rating |
|---|---|---|---|
| 8 chars | 52 bits | ~5 hours | Weak |
| 10 chars | 66 bits | ~2 weeks | Moderate |
| 12 chars | 79 bits | ~3 years | Strong |
| 14 chars | 93 bits | ~500 years | Very Strong |
| 16 chars | 106 bits | ~34,000 years | Very Strong |
| 20 chars | 133 bits | ~100 million years | Extremely Strong |
Password Security Rules
Minimum 12 characters
Length is the single most important factor for password strength
Use all character types
Uppercase, lowercase, digits, and symbols
Avoid personal info
Don't use names, dates, addresses, or phone numbers
Use a password manager
Generate and store unique passwords for every site
Enable 2FA
Two-factor authentication adds a critical second layer of security
Never reuse passwords
Each site should have a unique, unrelated password
Change compromised passwords
If a service is breached, change that password immediately
Use passphrases
Long, memorable word sequences are both strong and usable