Blog · Security guides

How to Create a Strong Password You Can Remember

Everyone knows the rules: long, random, unique, never reused. And almost nobody follows them, because human brains weren't built to memorize forty strings of gibberish. So people compromise — one "clever" password everywhere, maybe with an exclamation mark at the end — and that single compromise is how most account takeovers happen.

There is a better system, and it has two parts: passwords you can remember for the few accounts that matter most, and a password manager holding random ones for everything else. Here's how both work, plus the habits that actually move the needle.

What "strong" actually means

Strength is measured in entropy — bits of unpredictability. Each bit doubles the guessing work. An 8-character password of mixed characters has about 52 bits: crackable with serious hardware. Sixteen random characters push past 100 bits: effectively uncrackable by brute force, now and for the foreseeable future. The takeaway is simple and non-negotiable: length beats complexity. A 20-character passphrase of plain words crushes an 8-character tangle of symbols.

And forget the old P@ssw0rd! tricks. Attackers have dictionaries full of common substitutions. Randomness — not cleverness — is what protects you.

The passphrase method (for passwords you must remember)

Pick five or six truly random words and string them together: correct-horse-battery-staple is the famous example. Five random dictionary words give roughly 65 bits of entropy — strong enough for most purposes and genuinely memorable with a little repetition.

The critical word is random. "Sunshine-beach-summer-2024" feels personal but follows patterns attackers exploit. Use a generator or dice to pick words you would never naturally combine. Add a number or symbol between words if a site demands it.

The password manager (for everything else)

A password manager is the single biggest security upgrade most people can make. It generates and stores a unique 20+ character random password for every site, so you only ever memorize one strong master passphrase. When — not if — some site gets breached, the damage stops at that one account because nothing is reused.

Reputable options include Bitwarden (free and open source), 1Password, and Apple's and Google's built-in managers. Pick one, install the browser extension and phone app, and let it do the remembering. Generate the random passwords with Utilo's free password generator if you like — they're created with cryptographic randomness right in your browser and never leave your device.

Turn on two-factor authentication

Even the best password can leak. Two-factor authentication (2FA) means a stolen password alone isn't enough. Use an authenticator app (or hardware key for critical accounts) rather than SMS codes when you have the choice — SIM-swap attacks make text messages the weakest second factor.

What about passkeys?

Passkeys are the industry's answer to passwords altogether: cryptographic credentials stored on your phone or computer that log you in with a fingerprint or face scan — nothing to memorize, nothing to phish. Google, Apple, and Microsoft all support them now, and major sites are rolling them out. Where a site offers passkeys, take them; they're strictly better than any password. But passkeys aren't everywhere yet, and your password manager remains the bridge: it can store passkeys alongside passwords, so adopting them is a gradual upgrade, not a rip-and-replace. For the next few years, the winning setup is passkeys where offered, unique random passwords everywhere else, and a manager holding both.

Habits that actually matter

  • Unique everywhere. Reuse is the #1 killer. One breach + one reused password = every account exposed.
  • Change on cause, not on schedule. Current NIST guidance: rotate passwords after a breach or suspected compromise, not every 90 days. Forced rotation just produces Password1! → Password2!.
  • Watch breach notifications. Services like Have I Been Pwned tell you when your email appears in a leak — act on them.
  • Paper beats reuse. A notebook at home is far safer than one password everywhere. Remote attackers can't read your desk drawer.
  • Don't share over chat or email. If you must share access, use your password manager's sharing feature or a one-time secret link.

Frequently asked questions

What makes a password strong?

Length and randomness. A long random password beats a short complex one every time — 16+ random characters is the modern baseline, and 20+ is better.

Are passphrases really secure?

Yes, when the words are truly random rather than chosen to "make sense." Five random words give about 65 bits of entropy — strong, though a 20-character fully random password is stronger still.

Should I use a password manager?

Yes. It's the highest-impact security habit available: unique random passwords everywhere, one master passphrase to remember, breach damage contained to single accounts.

Is it safe to write passwords down?

A notebook kept at home is much safer than reusing passwords online — remote attackers can't read paper. A password manager remains the better option overall.

How often should I change passwords?

Only with cause: a breach, suspected compromise, or a weak original password. Scheduled rotation encourages weaker passwords, according to current NIST guidance.