Quick answer
Create a strong password by using a long, random, unique passphrase or a password-manager-generated string, never reusing it, and turning on two-factor authentication. If you choose it yourself, aim for at least 15 characters and use the longest limit the service allows.
A password is still a common way to enter an account, but it is not a complete security plan. A password can be guessed, stolen in a breach or handed to a fake sign-in page. Length helps, yet no password can protect an account from every kind of attack.
The practical goal is simple: make every password long enough, unpredictable and unique, then add another sign-in factor where the account supports it. NIST’s consumer guidance recommends at least 15 characters when you must create a password yourself, while its current technical guidance explains why length and usable passphrases matter more than forcing predictable mixtures of symbols. Use the account’s own limits as the final boundary.
1. Start on the real account page
Open the service’s app or type its known web address yourself. Do not create or change a password through a link in an unexpected email, text message or direct message. A convincing fake sign-in page can collect even an excellent password.
Look for Security, Account, Sign-in or Password settings. If you are responding to a breach notice, reach the provider through its normal app or a typed address rather than trusting the message’s button. The Federal Trade Commission’s account-protection guidance also treats two-factor authentication as an important layer beyond the password itself.
2. Decide whether you need to remember it
For most accounts, the safest practical choice is a password manager’s generator. It can create a different random password for each site and fill it without asking you to invent a new secret every week. CISA recommends long, random and unique passwords and identifies a password manager as the workable way to manage them.
Only a small number of passwords usually need to be memorized: the password-manager account, the main device passcode and perhaps a recovery credential. For those, use a deliberate passphrase. Do not force yourself to memorize every shopping, streaming and newsletter login.
3. Make it long enough
If you choose the password yourself, aim for 15 or more characters. A longer passphrase is often easier to remember than a short string of substitutions. If a service permits more characters, use that room; if it imposes a maximum, use the longest sensible value it accepts.
Do not treat 15 as a universal magic line. The account’s rules, threat model and second-factor options vary. NIST’s technical guidance says password length is a primary factor and encourages users to make passwords as long as they want within reason. It also explains that a long password still cannot stop phishing or keylogging.
4. Use unrelated words, not a familiar phrase
If the password must live in your memory, combine several words that were selected independently. For example, choose a few unrelated nouns rather than a sentence, quotation or lyric. Keep the example private: never copy a passphrase from an article, because anything published is no longer secret.
Avoid birthdays, names, addresses, pet names, sports teams, seasons and the service’s own name. Do not turn a predictable base into Summer2026! or change one digit each year. NIST notes that composition rules can lead users toward predictable variations, while familiar phrases can be guessed from common word and breach lists.
5. Prefer a generated string for ordinary accounts
A password manager can make a long random string that is difficult to invent and unnecessary to memorize. Let it choose the characters, length and permitted symbols, then save the result directly in the correct account entry. Do not copy a password into a public note, an unprotected document or a random “password strength” website.
The password-manager setup guide covers installation, import, unique logins and recovery planning. The important rule here is that the manager’s own password must be stronger and unique because it protects the rest of the vault.
6. Make every account’s password different
Never reuse an email password for banking, shopping, work or social media. Reuse turns one exposed account into a key that can be tried elsewhere. Similar passwords are not a safe compromise: changing the final number or adding an exclamation mark still reveals the pattern.
Use the same account entry only for the one service it represents. If a household shares a subscription, use the provider’s supported sharing feature rather than sending a password through ordinary chat. Keep work and personal credentials separate.
7. Handle awkward password rules carefully
Some sites reject spaces, symbols or long strings; others impose an old-fashioned mixture of uppercase, lowercase, numbers and symbols. Follow the site’s requirements, but do not respond with a predictable recipe. If spaces are allowed, a random passphrase can be easier to type. If they are not, use the longest random value the generator can make within the accepted character set.
Never weaken a password by making it shorter than necessary just to satisfy a form. If a service has an unusually low maximum or rejects a password manager’s generated value, use a unique alternative and rely on two-factor authentication as an additional layer. Consider contacting the provider through its official support channel if the rules make a secure password impractical.
8. Save the password only in a controlled place
A password should be available when you need it, not scattered across screenshots, browser notes, spreadsheets and old messages. A reputable password manager or the built-in manager on your device can be a reasonable place to store it; choose a tool you understand and protect its main account.
If you write down a memorized password during setup, keep the paper private and remove temporary copies when you no longer need them. Do not put credentials in a shared household document or a filename. Treat recovery codes and password-manager exports as sensitive material too.
9. Turn on two-factor authentication and test recovery
After saving the new password, open the account’s security settings and enable two-factor authentication if it is available. A second factor can help when a password is stolen, but it must be recoverable. Save the provider’s recovery codes in a protected place and add a backup method you control.
The two-factor authentication guide explains how to compare passkeys, security keys, authenticator apps and text messages, then test the sign-in before leaving the account. Never give a verification or recovery code to someone who contacts you unexpectedly.
10. Replace exposed or reused passwords first
If you discover that a password was reused, change the account with the greatest consequence first—usually primary email, a password manager or financial access—then work through every other place that used it. Use the provider’s official reset flow and sign out other sessions when the account offers that control.
Change a password promptly when it was entered on a fake page, included in a breach notice or shared with someone who should not have it. Make the replacement genuinely different. A new suffix, capitalization change or single symbol does not undo exposure of the original pattern.
| Situation | Better next move |
|---|---|
| You must remember the password | Use a long passphrase made from unrelated words |
| The account is ordinary or rarely used | Generate and save a unique random password in a manager |
| The site has a short maximum | Use the longest unique value it accepts and enable 2FA |
| The password was reused | Change the highest-risk account, then every other reuse |
| The password may be exposed | Reset it from the official site, review sessions and add 2FA |
Strong-password work is mostly a consistency problem, not a creativity contest. Use a manager for unique generated logins, use a long random passphrase only where memory is necessary, avoid publishing or reusing examples, and add two-factor authentication to the accounts that matter most. That routine is more useful than inventing one “perfect” password and using it everywhere.
Hero image: Book Catalog, CC BY 2.0, via Wikimedia Commons.
Sources
Frequently Asked Questions
What makes a password strong?
A strong password is long, difficult for someone else to predict and unique to one account. A password manager can generate and store a different random password for each site; if you must remember one, use a long passphrase made from unrelated words.
How many characters should a strong password have?
Aim for at least 15 characters when you choose a password yourself, and use a longer one when the service allows it. Requirements vary, so follow the account's limit without shortening a unique password unnecessarily.
Is a passphrase safer than a complicated password?
A passphrase made from random, unrelated words can be long and easier to remember than a short jumble. Do not use a familiar quotation, song lyric, predictable pattern or personal detail; a password manager is better for accounts that do not need a memorized password.
When should I change a password?
Change it when you know or suspect it was exposed, when you reused it on another account, after a provider reports a breach, or when an official recovery process tells you to. A new password should be genuinely different, not a small variation of the old one.