What Actually Makes a Password Strong
Length beats complexity. Here is why, and what to do about it.
Password strength is not a feeling about how odd a word looks. It is a measurement of how many guesses an attacker must make on average — and almost every intuition people have about it is wrong.
Entropy is the real measurement
Entropy counts the size of the space a password was drawn from, in bits. Each extra bit doubles the guessing work.
bits = length × log2(alphabet size)| Password style | Alphabet | Length | Entropy |
|---|---|---|---|
| Lowercase word | 26 | 8 | ~38 bits |
| Mixed case + digits | 62 | 8 | ~48 bits |
| Full ASCII, random | 95 | 12 | ~79 bits |
| Four random dictionary words | 7,776 per word | 4 words | ~52 bits |
| Six random dictionary words | 7,776 per word | 6 words | ~78 bits |
Why substitutions do not help
Replacing a with @ and o with 0 adds almost nothing, because cracking tools apply those exact substitution rules first. `P@ssw0rd!` is in every wordlist. The password has to be unpredictable to a program that already knows every trick humans reuse.
Length beats complexity
Adding one character to a random 95-symbol password multiplies the search space by 95. Adding a symbol requirement to a short one barely moves it. That is why a long passphrase of unrelated words outperforms a short cryptic string that is far harder to type on a phone.
- Aim for 16 characters or more when a site permits it.
- Prefer randomly generated passphrases over invented ones — human word choice is heavily clustered.
- Never reuse a password across sites; credential stuffing turns one breach into all of your accounts.
- Store everything in a password manager and only memorise the vault password and your device unlock.
The password generator produces cryptographically random strings, and the PIN generator does the same for numeric codes.
How fast can these be cracked?
Speeds depend entirely on how the site stored the hash. A password protected with bcrypt at a high work factor may allow only tens of thousands of guesses per second, while an unsalted MD5 database allows tens of billions.
| Storage | Guesses/second (single high-end GPU) | 10-char random password |
|---|---|---|
| Unsalted MD5 | ~100 billion | Hours |
| SHA-256 | ~10 billion | Days |
| bcrypt (cost 12) | ~20 thousand | Millions of years |
You do not control which of these a website uses, which is the strongest argument for both length and never reusing a password.
Two-factor authentication changes the maths
A stolen password becomes far less useful when a second factor is required. App-based codes and passkeys are meaningfully stronger than SMS, which is exposed to SIM-swap attacks. Where passkeys are offered, they eliminate the password from the login path entirely.
Frequently asked questions
How often should I change my password?
Only after a breach, a suspected compromise, or if it was ever reused. Forced rotation on a schedule makes people pick weaker, patterned passwords and is no longer recommended by NIST.
Are password managers safe?
Yes — the concentrated risk of one strong vault is far lower than the distributed risk of reused passwords across dozens of sites. Choose one with a published security audit and enable two-factor on it.
Is a passphrase of four words still enough?
Four truly random words is about 52 bits, which is adequate for accounts behind rate limiting but thin against an offline attack. Six words puts you comfortably out of reach.
Does adding a number at the end help?
Barely. Appending a digit is the first mangling rule every cracking tool applies, so it costs an attacker roughly one extra second of work.