Security

How to make a strong password you can actually remember

Birthdays, phone numbers, "Password1!" — attackers try these first. Here's how to make passwords that are both strong and manageable.

How passwords get broken

  • Credential stuffing — leaked username/password pairs from one site are tried on others. Reusing a password means one breach unlocks everything.
  • Common-password lists — 123456, qwerty, password1 and thousands more are tried first.
  • Personal details — names, birthdays and pets found on social media.

Length beats complexity

Password typeApprox. strength
8 lowercase letters~38 bits
8 mixed characters with symbols~52 bits
12 letters + digits~71 bits
16 random characters of every type100+ bits

Every extra bit doubles the guessing effort, which is why a random 16-character password is vastly stronger than a "complex" 8-character one.

Memorable passwords: random words

Something like Maple-orbit-kettle-dune-47 is easy to remember and hard to guess — as long as a computer chose the words. People pick predictable words, so use the "memorable words" option in the password generator as-is, and use five or more words for important accounts.

A realistic system

  1. Memorize two or three strong ones — your email, your password manager or browser account, and your phone.
  2. Generate and save the rest in your browser's password manager or a dedicated app.
  3. Turn on two-factor authentication, starting with email and banking.

Our generator uses your browser's cryptographic random source (crypto.getRandomValues) and never stores or sends what it creates.

Written by · Fingertip Workshop

I got tired of searching for the same small computer chores, so I started building the tools myself. Every tool here is used and refined before it goes on the shelf, and every guide comes from a real problem.