Password Strength & Creation Guide: Building Passwords That Actually Hold Up
Most password advice focuses on the wrong thing. Here's what genuinely makes a password hard to guess, and a repeatable method for creating one.
What "Strength" Actually Means Beyond Length
A password is "strong" to the extent that an attacker who already knows your username, and has unlimited guesses against an offline copy of the hash, would need an impractically long time to find it. That's the entire definition. It has nothing to do with whether the password looks complicated to a human, or whether it satisfies a checklist of character-type requirements. A 20-character phrase built from ordinary lowercase words can be dramatically stronger than an 8-character string stuffed with symbols, purely because of how many possible combinations an attacker has to search through.
This distinction matters because a lot of password policies were written by people optimizing for the wrong thing β making a password look unguessable to another human, rather than making it statistically hard for a machine to search. Once you internalize that strength is a search-space problem, most of the rest of this guide follows naturally.
Length vs Complexity: What the Evidence Actually Shows
Every additional character you add to a password multiplies the total number of possible passwords by the size of your character set. Adding length is almost always a better use of your effort than adding complexity, because length compounds multiplicatively across every position in the password, while a symbol or capital letter only adds a fixed, one-time boost to the character set size for that specific position.
Concretely: going from a 10-character password using only lowercase letters to a 14-character password using only lowercase letters increases the search space far more than keeping it at 10 characters and forcing in three symbols and two digits. This is why current guidance from security researchers and standards bodies has shifted heavily toward "just make it longer" rather than "make it look more complicated."
NIST SP 800-63B Guidelines and Why They Changed Everything
The U.S. National Institute of Standards and Technology publishes digital identity guidelines that much of the security industry treats as a de facto standard, and its password-specific document (SP 800-63B) triggered a genuine shift in how organizations think about password policy. The core recommendations: prioritize minimum length (8 characters minimum, with longer strongly encouraged) over mandatory complexity rules; stop requiring periodic password expiration unless there's actual evidence of compromise; and instead screen new passwords against lists of known-breached and commonly-used passwords, rejecting matches outright.
This represented a direct reversal of decades of prior guidance from the same standards bodies. The earlier approach β mandatory symbol/number/capital requirements plus forced rotation every 60β90 days β had been standard corporate practice for so long that many organizations still enforce it today, despite the evidence showing it drives predictable, weaker password choices rather than stronger ones.
A Step-by-Step Method for Building a Password Manually
If you need to create a password without a generator β for a service that restricts character types unusually, or simply because you prefer to type your own β here's a repeatable method that avoids the common traps:
- Start with length, not characters. Decide on a target length first β 16 characters is a reasonable baseline for most accounts, more for anything high-value.
- Pick a structure you can vary per site. A fixed personal "core" plus a site-specific unique segment defeats reuse risk, but only if the site-specific part is genuinely unpredictable, not just the service's name spelled out.
- Avoid substituting the obvious way. Swapping "a" for "@" or "e" for "3" follows a pattern attackers' cracking dictionaries already account for β it barely raises effective strength despite looking more complex.
- Check it against a strength estimator before committing to it for a real account β ideally one that estimates crack time rather than just displaying a color bar.
The Passphrase Method in Practice
A passphrase β several unrelated words strung together β solves the tension between strength and memorability better than almost any other manual method. The key word is unrelated: four words that form a coherent, memorable phrase ("mydogisnamed spot") draw from a far smaller effective pool than four words picked independently at random from a large word list, because natural language is predictable and grammatically-structured phrases are exactly what a sophisticated cracking dictionary targets first.
The correct construction method (popularized by the Diceware system and the EFF's own word lists) is to select words independently and randomly, not to compose a sentence. Four to six words picked this way from a list of a few thousand candidates already produces entropy comparable to a fully random 12β16 character password, while remaining genuinely easier to recall and type accurately than an equivalent-strength random string.
Common Patterns That Feel Random But Aren't
Certain password habits feel creative to the person choosing them but are so common across the population that cracking tools specifically test for them early. Keyboard-walk patterns (qwerty, 1qaz2wsx), a capital letter only at the start with a number only at the end (Password1), a name followed by a birth year, and doubling a short word (passpass) all fall into this category. None of these substantially increase resistance to a targeted or automated guessing attack, regardless of how unfamiliar the pattern feels to the person who chose it.
The deeper issue is that humans are consistently bad at generating true randomness under instruction β a well-documented finding across decades of research, not a personal failing. This is precisely why cryptographically random generation (via a tool like our Password Generator, or dice for an offline method) reliably outperforms manual invention, no matter how deliberately unpredictable the manual attempt feels to its creator.
Password Strength Meters: What They Measure and Where They Lie
The colored strength bar under a password field on most signup forms is doing one of two very different things, and it's rarely obvious which. Simple meters award points for character-type variety and length thresholds β a checklist approach that a pattern like "Password1!" satisfies easily despite being trivially guessable. More sophisticated meters (the open-source zxcvbn library being the best-known example) actually simulate pattern-matching and dictionary-based cracking attempts against the input, producing an estimate that correlates far better with real-world guessing resistance.
The practical takeaway: a green "strong" bar on a checklist-style meter tells you almost nothing about actual crack resistance. If you want a genuine strength estimate, look for a meter that displays an actual estimated crack time rather than a bar-and-color rating, or generate your password with a tool that calculates entropy directly rather than relying on a signup form's built-in judgment.
Memorization Techniques That Don't Compromise Security
For the few passwords you genuinely need to recall without a manager's help, a handful of memorization techniques work without reintroducing predictability. Chunking a long random string into groups of four characters (the way a credit card number is displayed) measurably improves recall accuracy without changing the underlying password at all. Visualizing a passphrase's words as an absurd, vivid mental scene β the classic "memory palace" technique β works because unusual imagery is inherently more memorable than the words in isolation, without needing to alter the words themselves toward something more predictable.
What doesn't work, despite feeling intuitive: writing a partial hint on a sticky note, using a personally meaningful but externally-discoverable fact (a pet's name, a street you grew up on), or intentionally weakening a passphrase into a grammatically correct sentence to make it "flow" better β all of these trade real security for a small, often unnecessary convenience gain.
Organizational Password Policies: What Actually Works
For anyone setting password policy for a team rather than just their own accounts, the evidence-backed approach looks meaningfully different from the traditional corporate checklist. Rather than mandatory complexity rules and 90-day rotation, current best practice favors: a generous minimum length (12+ characters), automated screening against known-breached password lists at creation time, mandatory MFA on any account with elevated privileges, and password changes triggered only by actual evidence of compromise rather than an arbitrary calendar.
Organizations that still enforce old-style rotation policies often see users respond by incrementing a single base password (Summer2024! becomes Summer2025! the following quarter) β a pattern that technically satisfies "the password changed" while providing essentially no real security benefit, and one that automated cracking tools specifically account for when testing accounts known to be subject to rotation policies.
Real Daily-Use Scenarios
Scenario 1 β Signing up for a new streaming service: This is a genuinely low-stakes account, and spending five minutes crafting a memorable passphrase is disproportionate effort. The right move is a quick, unique password generated on the spot (via a password manager or our Password Generator) and saved immediately β strong enough to resist casual guessing, unique enough that a future breach at this one service can't cascade anywhere else.
Scenario 2 β Setting a corporate email password under a legacy complexity policy: Your IT department still requires one uppercase letter, one number, and one symbol, with mandatory 90-day rotation. Rather than incrementing a base password each quarter (Summer2025! β Summer2026!), generate a genuinely new, fully random string each rotation that happens to satisfy the character-type checklist, and store it in a password manager rather than trying to memorize a new complex string every quarter.
Scenario 3 β Choosing your password manager's master password: This is the one password across your entire digital life that genuinely deserves the passphrase method covered earlier β five or six independently-chosen random words, memorized carefully, since losing this one password potentially locks you out of every other credential you own.
Scenario 4 β Setting a home Wi-Fi router's admin password: Router admin panels are frequently left on factory-default credentials for years, since they're rarely typed after initial setup. A strong, randomly generated password stored in a password manager (rather than left as "admin/admin") closes off a genuinely common home-network attack vector at essentially zero ongoing inconvenience.
Password Managers: Reducing How Often Manual Creation Matters
Everything this guide covers about manual password construction becomes far less necessary in daily practice once a password manager handles generation and storage for the vast majority of your accounts. A password manager removes the tension this entire guide has been navigating β strength versus memorability β for every account except the one securing the manager itself, since a manager-generated password never needs to be recalled or manually typed again after creation.
This doesn't make the manual creation method obsolete, though. Understanding why long, random passphrases and strings work the way they do makes you a better judge of your password manager's own security claims, helps you set an appropriately strong master password, and gives you a reliable fallback method for the occasional service that restricts password managers or requires manual entry on a device where autofill isn't available.
Testing Your Own Passwords Safely
Checking whether a password has already appeared in a known data breach is a legitimate and useful practice β but it should be done carefully. Reputable breach-checking services use k-anonymity techniques (transmitting only a partial hash prefix, never the full password or hash) specifically so the service itself never receives your actual password. Never paste a real, currently-in-use password into an unfamiliar tool or form to "test" it β if the site isn't using a verified privacy-preserving method, you've potentially handed a working credential to whoever operates it.
A safer habit: test a candidate password for reuse and predictability before you commit to using it on a real account, using a generator's built-in entropy estimate rather than submitting the final password to a third-party checking tool at all.
Multi-Factor Authentication as a Complement, Not a Replacement
Even a genuinely strong, uniquely-generated password addresses only part of real-world account risk. Multi-factor authentication adds a second, independent verification step β a code from an authenticator app, a hardware security key, or a biometric check β so that a compromised password alone no longer guarantees account access. This matters because several of the most damaging real-world compromises (phishing, keylogging malware, database breaches at other services) capture or expose a password directly, bypassing whatever strength that password actually had entirely.
The practical relationship between the two: strong, unique passwords protect specifically against guessing-based attacks like brute force and credential stuffing, while MFA protects against the broader set of scenarios where the password itself has already been compromised through some other means. Treating them as complementary layers, rather than choosing one over the other, reflects how real account security actually works in practice.
FAQ
ToolsNovaHub guides are researched against primary sources (RFCs, vendor docs) and kept up to date as standards change. Spotted an error? Let us know.
π Related Tools & Guides Comparison
| Resource | Type | Link |
|---|---|---|
| Password Generator | Tool | Open Tool β |
| Email Checker | Tool | Open Tool β |
| Password Generator Guide | Guide | Read Guide β |
| Password Hashing vs Encryption Explained | Guide | Read Guide β |
| Common Password Attacks & Risks | Guide | Read Guide β |