← All guides

How to create a strong password: length, randomness and a password manager

· 2 min read

A strong password is not a clever phrase you can remember; it is a long, random string of characters. The passwords people choose follow predictable patterns, and computers try those patterns first.

Length matters more than variety

Every extra character multiplies the number of guesses needed. A complex 8-character password is much easier to crack than a plain 16-character one. For most accounts, at least 16 characters is a good target.

What is entropy?

Entropy expresses, in bits, how hard a password is to guess. For a randomly generated password the rough calculation is:

entropy ≈ length × log2(size of the character pool)

Example: 16 characters, pool of 94 (letters, digits, symbols)
16 × log2(94) ≈ 16 × 6.55 ≈ 104 bits

This calculation only holds for truly random passwords. A word or pattern you choose yourself carries far less entropy.

Why randomness matters

People use birth years, names, keyboard patterns and things like "Password123!". Attackers' dictionaries try these patterns first. For real randomness, a tool that uses the browser's secure random number generator (crypto.getRandomValues) is far better than "mixing it up" by hand.

A different password for every account

If one site suffers a data breach, every other account that shares the password is at risk. Using a different password for each account is far safer than reusing one strong password everywhere.

Use a password manager

Nobody can memorise dozens of long random passwords. A trustworthy password manager keeps them in an encrypted vault and fills them in for you. Generate a password with the tool, then save it straight into your manager. Turn on two-step verification where you can.

Try it yourself

In the password generator, choose the length and character types: the password is generated in your browser and an approximate entropy value and strength level are shown. Your password is never sent or stored.

This article is general information. For critical accounts, also follow your organisation's security policy.

More guides