Most password advice used to focus on complexity: a capital letter, a number, a symbol. Modern guidance, including the US National Institute of Standards and Technology’s digital identity guidelines (NIST SP 800-63B), puts much more weight on length and on avoiding passwords that are common or have already been leaked.

Why predictable passwords fail

Attackers don’t guess one character at a time. They try lists of leaked passwords, dictionary words and common patterns first — such as Summer2026! or P@ssw0rd. Swapping letters for look-alike symbols is a pattern too, and cracking tools apply those substitutions automatically.

A randomly generated password has no pattern to exploit. The only way to crack it is to try combinations, and the number of combinations grows very quickly with length.

How strength is measured

For a random password, strength is usually expressed as entropy in bits: length × log₂(size of the character pool). Each extra bit doubles the number of guesses needed.

  • 12 random lowercase letters: about 56 bits.
  • 12 random characters from upper, lower, digits and symbols: about 78 bits.
  • 20 random characters from the same mix: about 130 bits.

Adding length is the most effective way to add strength.

Practical rules

  1. Use a different password for every account, so one breach doesn’t unlock others.
  2. Make passwords long and random — 16 characters or more where the site allows.
  3. Store them in a password manager rather than trying to remember them.
  4. Turn on two-factor authentication for email, banking and anything important.
  5. Change a password promptly if a service tells you it has been involved in a breach.

Passwords you need to type

For the few passwords you must remember — your password manager’s master password, for example — a passphrase of several randomly chosen words can be easier to type and recall while remaining strong. The key word is randomly: a famous quote or song lyric is not random.

Generate one now

The password generator uses your browser’s cryptographically secure random number generator and shows an entropy-based strength estimate. The password is created on your device and is never transmitted or stored.