How Strong Should a Password Be?
October 9, 2026 · 4 min read
A strong password should be long, unique to one account, and difficult to predict. For a generated password, 16 or more random characters is a practical baseline when the service permits it; for a memorized passphrase, use several unrelated words and avoid familiar quotations, personal facts, and common patterns.
Length is only part of the answer. Reusing a superb password across sites turns one breach into access to several accounts. Use a password manager to store a different value for every login, and use the password generator to create random values locally with the character groups and length you choose.
Length beats forced complexity
Each additional unpredictable character expands the number of possible passwords. That is why a longer random password generally gains more strength than a short password decorated with a capital letter, a digit, and a predictable symbol at the end.
Complexity rules can help only when they expand genuine randomness. Password1! meets many checklists but follows a common human pattern. Replacing letters with obvious symbols, capitalizing the first character, or appending the current year does not make a short, familiar phrase reliably strong.
Use the longest unique random password a site and your password manager can handle comfortably. When a service imposes a lower maximum, fill much of the available length with generated characters instead of trying to invent something clever.
Entropy in plain words
Entropy is a way to describe how many possibilities an attacker would need to consider when the creation method is known but the exact result is not. More possible results mean more bits of entropy. One extra bit doubles the number of possibilities.
Randomness must come from the generation process, not from how unusual a password looks afterward. A 20-character result selected uniformly from a broad pool has a measurable search space. A human-made sentence may contain 20 characters but have much less uncertainty because language, names, dates, keyboard paths, and substitutions are predictable.
The generator shows an estimated bit count based on length and the enabled character pool. Treat it as a comparison aid for generated values, not proof that a hand-edited password is equally random and not a check against passwords exposed in past breaches.
Passphrases you can remember
A passphrase combines multiple words to create length while remaining easier to type and remember. The words should be selected independently rather than forming a famous quote, lyric, proverb, movie line, or personal story. Attackers can test those recognizable sources early.
If you choose words yourself, avoid names, birthdays, pets, teams, addresses, and facts visible on social profiles. A password manager can generate word-based passphrases where supported, or you can use a trustworthy random-word method. Do not reuse the same passphrase with small site-specific changes.
Passphrases are especially useful for the password manager’s own master password because you must remember it. Most other account passwords do not need to be memorable at all; let the manager create and fill random strings.
Password reuse is the real danger
When a site leaks login data, attackers may try the same email and password on unrelated services. If you reused that password, the attacker does not need to crack the stronger site. A unique password limits the damage to the account where it was exposed.
Small variations are not reliable isolation. Changing River!27 to River!28 or adding a site name creates a pattern that can be guessed once one version is known. Generate an unrelated value for every account, including low-priority accounts that share your email address.
If you discover reuse, change the email account and password manager first, then financial, work, shopping, social, and other accounts. Review active sessions and recovery details as you go. Never wait for visible misuse before replacing known exposed credentials.
Use a password manager and two-factor authentication
A password manager stores unique credentials in an encrypted vault and fills them on the correct sites. It removes the pressure to memorize dozens of random strings. Protect the vault with a strong, unique master passphrase and follow the provider’s recovery guidance before you need it.
Two-factor authentication adds another requirement after the password. An authenticator app, security key, passkey, or other second factor can block many account takeovers when a password is stolen. Prefer stronger options offered by the service; SMS is still better than password-only access in many situations, but phone-number attacks and message interception are concerns.
Keep recovery codes in a protected location separate from the device used for sign-in. Two-factor authentication complements unique passwords; it does not make reuse or weak recovery questions safe.
How to generate a strong password with Tools on Deck
The local password generator creates passwords on your device with the browser’s cryptographic random source. It supports lengths from 4 to 128, up to 50 results at once, and guarantees at least one character from every enabled group.
- Set Length to at least 16 for a typical generated account password, or longer when the service allows it.
- Keep uppercase, lowercase, numbers, and symbols enabled unless a site rejects a group.
- Enable Exclude look-alikes when you may need to read or type the value manually.
- Generate one password, or choose a batch only when you have a clear secure destination for every result.
- Review the estimated entropy as a relative strength indicator, then copy the password directly into your manager.
- Save it to the correct account record and avoid sending it through notes, chat, or email.
Quick answer: how strong is strong enough?
For most accounts, choose a unique manager-generated password of at least 16 random characters and use more length where accepted. A shorter password can still be strong under some generation rules, but extra random length gives you margin without requiring memorization.
For a master password you must remember, use a long passphrase made from several unrelated randomly selected words. Add two-factor authentication, protect recovery methods, and replace any password that is reused, exposed, phished, or shared. Strength is a system: randomness, length, uniqueness, storage, and account recovery all matter.