deftivo

How to Create a Strong Password (and Keep Track of It)

Learn how to create a strong password: why length matters, patterns to avoid, passphrases, password managers and 2FA, plus a free random password generator.

Most of us have dozens of accounts, from email and banking to shopping sites and streaming services. Each one asks for a password, and it’s tempting to reuse one you can remember or add a “1!” to the end of an old one. The trouble is that attackers know these habits well, and their tools are designed to exploit them.

This guide is for anyone who wants better passwords without having to memorize long strings of symbols. You’ll learn what actually makes a password strong, which patterns to avoid, how password managers and two-factor authentication fit in, and how to make a random password in a few seconds.

Why length matters more than complexity

When attackers try to crack a password, they usually don’t guess by hand. They use software that tries huge numbers of combinations very quickly. It starts with the most likely guesses, such as common words, names, dates and known leaked passwords, and moves on to every possible combination if those fail. That last approach is called a “brute-force” attack.

Every character you add makes a brute-force attack much harder. The number of possible passwords is multiplied by the size of the character pool for each extra character. A short password with lots of symbols can still be weaker than a longer one made of simpler characters. Length has the biggest effect, and using different kinds of characters helps on top of that.

A practical rule is to use 16 characters or more for passwords a tool creates for you. For passwords you have to type from memory, a long passphrase (covered below) is usually easier to manage.

Patterns to avoid

Cracking tools are built around how people usually make passwords. If your password follows a common pattern, it can be guessed early, however clever it looks. Avoid:

  • Dictionary words and names, including names of pets, family members, sports teams or places.
  • Dates, such as birthdays, anniversaries or years.
  • Keyboard walks, like “qwerty”, “asdfgh” or “1qaz2wsx”.
  • Predictable substitutions, such as “p@ssw0rd” or “S3cur1ty”. Swapping letters for similar-looking symbols is one of the first tricks cracking software tries.
  • Capital letter first, number and symbol last, as in “Summer2024!”. This is extremely common, so it’s one of the first things tools check.
  • Personal information that someone could find on your social media profiles.

The safest way to avoid patterns is to let randomness choose for you, because people are poor at producing truly random choices.

The real danger: password reuse

Even a strong password becomes a weak point if you use it on more than one site. When a website is breached, stolen usernames and passwords often end up in lists shared among attackers. They then try those same combinations on other popular services. This is called “credential stuffing,” and it works because so many people reuse passwords.

If every account has its own password, a breach at one site stays at that site. You only have to change one password rather than scramble to secure everything you own. Unique passwords are arguably more important than any other single tip in this guide.

Comparing your options

Here’s how the common approaches compare:

Approach Strength Easy to remember? Best for
Short, familiar word with tweaks (“Fluffy123!”) Weak Yes Nothing. Avoid it
Same strong password everywhere Weak overall (one breach exposes all) Yes Nothing. Avoid it
Random string from a generator Very strong No Accounts stored in a password manager
Passphrase of random words Strong when long enough Fairly easy Master password, device logins
Any of the above + two-factor authentication Much stronger protection Depends Email, banking and other important accounts

The best setup combines these: random passwords saved in a password manager, one memorable passphrase to unlock the manager, and two-factor authentication on your most important accounts.

Password managers: the key to making this practical

A password manager is an app that stores your passwords in an encrypted vault. You remember one strong master password, and the manager remembers the rest. Most can fill in login forms for you, sync across your devices and warn you about reused or weak passwords.

There are several kinds. Some are built into web browsers or operating systems, others are standalone apps, and some store your vault in the provider’s cloud so it syncs between devices, while others keep it only on your own device. Each approach has trade-offs between convenience and control, so pick the one that matches how you work. The important thing is to use one consistently.

Your master password is the one password you really need to memorize, so make it a long passphrase and don’t use it anywhere else.

Passphrases: strong and memorable

A passphrase is a password made of several words, such as “lantern-oyster-gravel-mitten-orbit”. Because it’s long, it’s hard to brute-force, and because it’s made of real words, it’s easier to remember and type than a random string.

To make a good passphrase:

  • Choose the words randomly. Don’t use a song lyric, quote or phrase that means something to you. Methods like rolling dice against a word list work well.
  • Use at least four or five words. More words means more strength.
  • Keep the words unrelated. “Blue-sky-sunny-day” follows a natural pattern and is easier to guess.
  • Add a separator such as a hyphen if you like, as long as it doesn’t make the passphrase shorter or more predictable.

Passphrases are ideal for your password manager’s master password and for logins you have to type often, like your computer.

Two-factor authentication: a second lock

Two-factor authentication (2FA) asks for something extra besides your password, usually a short code or a tap on your phone. Even if someone steals your password, they still can’t log in without that second factor.

Common options include:

  • Authenticator apps, which generate a new code every short period.
  • Text message codes, which are convenient but generally considered less secure than an app, because phone numbers can sometimes be hijacked.
  • Hardware security keys and passkeys, which use a physical device or your phone’s built-in security and are strongly resistant to phishing.

Turn on 2FA for your email first. Password resets for most other accounts go through your email, so it’s the key to everything else.

How to generate a strong password with Deftivo

The Deftivo password generator runs entirely in your browser, so the passwords it creates aren’t sent to a server. Here’s how to use it:

  1. Set the length. 16 or more is a good default. Go longer if the website allows it.
  2. Choose which kinds of characters to include, such as uppercase letters, lowercase letters, numbers and symbols. If a site rejects certain symbols, turn them off and add a little extra length instead.
  3. Copy a password and save it in your password manager. Save it straight away, before you close the tab, so you don’t lose it.

Repeat this for each account, so every site gets its own unique password.

Tips and pitfalls

  • Start with your most important accounts. Update email, banking and your password manager first, then work through the rest over time.
  • Don’t store passwords in plain notes or spreadsheets. A password manager encrypts them, but a text file doesn’t.
  • Save your 2FA backup codes. If you lose your phone, these codes let you back into your accounts. Keep them somewhere safe and offline.
  • Watch out for phishing. A strong password doesn’t help if you type it into a fake login page. Password managers help here, because they usually won’t autofill on a lookalike site.
  • Don’t change strong passwords for no reason. Change a password if a site reports a breach or you suspect someone has it. Constant forced changes tend to push people toward weaker patterns.

FAQ

How long should my password be?

For passwords stored in a password manager, 16 characters or more is a sensible default, and longer is fine if the site allows it. For passwords you type from memory, a passphrase of several random words gives you length without the memorization headache.

Are passphrases really as secure as random passwords?

A passphrase made of enough truly random words can be very strong, because its length makes brute-forcing hard. The key is randomness: words you pick yourself, or a well-known phrase, are much easier to guess. For accounts you never type by hand, a generated random password is simpler.

Is it safe to use an online password generator?

It depends on how the tool works. The Deftivo password generator creates passwords in your browser, and nothing is uploaded. Whatever tool you use, save the result directly to your password manager rather than pasting it somewhere else.

What if a website won’t accept my generated password?

Some sites limit length or reject certain symbols. Go back to the generator, turn off the character types the site doesn’t allow, and adjust the length to fit within its limit. Then generate a new password and save it to your password manager.

More guides