Security
How to make a strong password you can actually remember
Birthdays, phone numbers, "Password1!" — attackers try these first. Here's how to make passwords that are both strong and manageable.
How passwords get broken
- Credential stuffing — leaked username/password pairs from one site are tried on others. Reusing a password means one breach unlocks everything.
- Common-password lists — 123456, qwerty, password1 and thousands more are tried first.
- Personal details — names, birthdays and pets found on social media.
Length beats complexity
| Password type | Approx. strength |
|---|---|
| 8 lowercase letters | ~38 bits |
| 8 mixed characters with symbols | ~52 bits |
| 12 letters + digits | ~71 bits |
| 16 random characters of every type | 100+ bits |
Every extra bit doubles the guessing effort, which is why a random 16-character password is vastly stronger than a "complex" 8-character one.
Memorable passwords: random words
Something like Maple-orbit-kettle-dune-47 is easy to remember and hard to guess — as long as a computer chose the words. People pick predictable words, so use the "memorable words" option in the password generator as-is, and use five or more words for important accounts.
A realistic system
- Memorize two or three strong ones — your email, your password manager or browser account, and your phone.
- Generate and save the rest in your browser's password manager or a dedicated app.
- Turn on two-factor authentication, starting with email and banking.
Our generator uses your browser's cryptographic random source (crypto.getRandomValues) and never stores or sends what it creates.