How to Create a Strong Password You Can Actually Remember
Forget the capital letter, the number and the exclamation mark at the end. A long string of random words is easier to remember and far harder to guess, and a unique password for every account matters even more.
By the Fileora team7 min read
Most of us learned the same recipe: take a word, capitalise it, swap an o for a zero and add a number and a symbol. The result is hard to remember and, as it turns out, easy to crack. The advice has changed, and the new version is kinder to your memory.
Length beats complexity
Password crackers don't try every combination of characters in order. They start with lists of leaked passwords and dictionary words, then apply the tweaks people make most often: a capital at the start, a year at the end, @ for a, 0 for o. A password like Liverpool1990! ticks every box on an old-style sign-up form, yet it is a football club, a year and a symbol in the most predictable positions.
What makes a password hard to guess is how many possibilities an attacker has to work through, and that grows fastest with length. Each extra random character multiplies the total. Forcing yourself to include a symbol adds far less than simply adding a few more characters, and it pushes you towards the predictable tricks attackers already expect.
The standards bodies now say this plainly. The current US guidance, NIST SP 800-63B (Revision 4), tells websites and services that:
- passwords used on their own must be at least 15 characters; passwords used alongside a second factor must be at least 8
- they should allow passwords of at least 64 characters
- they must not impose composition rules such as "one uppercase, one number, one symbol"
- they must not make you change passwords on a schedule, only when there is evidence one has been compromised
- they must check new passwords against a list of common, expected and previously breached passwords
- they must allow password managers and autofill, and should let you paste
Many websites haven't caught up yet, so you will still meet forms that demand a symbol or expire your password on a fixed schedule. That's the site's rule, not a sign that complexity is what keeps you safe.
Passphrases: random words you can picture
The easiest way to get length without pain is to string together several unrelated words. The UK's National Cyber Security Centre recommends combining three random words, with applenemobiro as its example. It also warns against swapping letters for numbers, because criminals know those tricks too, and against using birthdays, family names, pet names or your favourite team, since so much of that is public on social media.
The key word is random. A phrase you chose because it means something to you, a song lyric or a line from a film, is much weaker than one picked by chance. The most reliable way to pick words by chance is to let dice or a computer do it. The Electronic Frontier Foundation publishes a dice method: roll five dice, look the number up in its long word list of 7,776 words, and repeat. It suggests six words, which gives roughly 277 possible passphrases.
Here's how the numbers work when words are picked truly at random from a list that size:
| Words picked at random from 7,776 | Possible passphrases | Roughly equivalent to |
|---|---|---|
| 3 | about 470 billion | 6 random letters, digits and symbols |
| 4 | about 3.7 quadrillion | 8 random characters |
| 5 | about 2.8 × 1019 | 10 random characters |
| 6 | about 2.2 × 1023 | 12 random characters |
The comparison assumes about 90 possible characters per position. Each random word adds roughly as much as two random characters, and a word is far easier to remember than k7#Q.
Making a passphrase stick
- Picture it. Turn the words into a silly scene: a kettle wrapped in ribbon sliding down a glacier. Absurd images are easier to recall.
- Type it a few times the day you create it. Muscle memory does the rest.
- Keep the separator simple. Spaces, hyphens or nothing at all are fine. If a site insists on a capital and a number, add them, but don't rely on them for strength.
Reuse is the real danger
A strong password stops someone guessing it. It does nothing if the site you used it on is breached and the password leaks. Attackers then take the leaked email and password pairs and try them automatically on email providers, banks and shops. This is called credential stuffing, and OWASP describes it as working precisely because many people use the same username and password in more than one place.
So the most useful habit is simple: one password per account. Start with the accounts that unlock others. Your email comes first, because anyone who controls your inbox can reset almost everything else. The NCSC specifically advises a strong and separate password for email that you don't use anywhere else.
Let a password manager remember the rest
Nobody can memorise a different strong password for dozens of accounts, and you shouldn't try. A password manager stores them, fills them in, and can create a new random one each time you sign up. The one built into your browser or phone is a reasonable start.
You then only need to remember a few passphrases: for the manager itself, your main email and perhaps your computer. Everything else can be a long random string you never see.
For those random strings, our password generator makes character passwords of 4 to 128 characters on your own device, using the browser's secure random number generator. It doesn't make word-based passphrases. Its default, 16 characters from uppercase, lowercase, numbers and symbols, comes out at about 103 bits, far beyond the reach of brute force.
Turn on two-step verification and passkeys
A second step means a leaked password on its own isn't enough to get in. The NCSC recommends 2-step verification on your important accounts: email, banking, social media and shopping. You'll usually find it in the account's security settings.
Where a site offers a passkey, it's worth trying. A passkey replaces the password with a cryptographic key stored on your phone, computer or security key, and you unlock it with the same fingerprint, face or PIN you use for the device. According to the FIDO Alliance, passkeys resist phishing and there is no password on the server for anyone to steal.
Has your password already leaked?
Have I Been Pwned lets you check whether your email address appears in known data breaches, and can email you if it turns up in a future one. That is the safe place to start: it tells you which accounts need a new password without you typing any password at all.
The same service runs Pwned Passwords, a database of passwords seen in breaches. Its password search hashes what you type on your own device and sends only the first five characters of the SHA-1 hash, then compares the results locally, so the password itself isn't transmitted. Even so, the safer habit is not to type a live password into any website. Some password managers check your saved passwords for you; Google Password Checkup, for example, flags ones that are exposed, weak or reused.
Test the pattern, not the real thing
To see how a style of password holds up, use the password strength checker. It looks for the shortcuts crackers take, such as about 200 of the most leaked passwords, common words, symbol swaps, keyboard runs, years and dates, then estimates the guesses needed and the time to try them: at roughly 100 per hour for a throttled login page, 10,000 per second for stolen bcrypt-style hashes, and 10 billion per second for fast hashes cracked on GPUs. Liverpool1990! scores 2 out of 4 and falls instantly in the fast-hash case.
The check runs in your browser and makes no network requests with what you type. Still, test something similar in shape to your real password, not the password itself. Two limits to keep in mind: it does not check breach databases, and its word list is small, so a passphrase of uncommon words is treated as random letters and can look stronger than it really is. For a random passphrase, the table above is the better guide.
A quick checklist
- Your email, password manager and main device each have a long, unique passphrase of five or six random words.
- Every other account has its own random password, stored in a password manager.
- Two-step verification is switched on for email, banking and social media, with passkeys where offered.
- Your email address is registered for breach alerts, and anything flagged gets a new password straight away.
- No password includes your name, birthday, pet, street or team.
Once this is set up, you'll remember fewer passwords than before, and the ones you do remember will be the strongest you've had.