What makes a password strong (and what doesn't)
Password advice has calcified into theatre: insert a symbol, capitalise a letter, swap an o for a zero, and the little strength meter turns green. Meanwhile attackers crack such passwords in minutes, because strength was never about decoration. It is arithmetic — a count of how many guesses an attacker must make on average before landing on yours. Once you internalise that arithmetic, most popular tips reveal themselves as noise, and two boring habits emerge as the ones that actually protect accounts: enough length, and never reusing anything anywhere. This article walks through the maths gently, explains why the tricks you were taught are already automated, and ranks the changes that genuinely move the needle.
Length beats symbol soup
Picture cracking as a search through every possible combination. Each additional random character multiplies the search space by the size of the character pool. Eight random lowercase letters yield 26 raised to the power 8 — roughly 209 billion possibilities, or about 37.6 bits of entropy. Twelve characters drawn from the full printable keyboard, around 94 possible symbols, multiply out near 78.7 bits, which is trillions upon trillions of times harder. Notice where the leverage came from: stretching eight lowercase letters to twelve added about 15 bits, while widening the alphabet at twelve characters added another 24. The effects compound multiplicatively, which is why a sixteen-character random string crushes any nine-character punctuation-decorated dictionary word regardless of how clever its symbols look.
Substitution tricks are already in the wordlist
Cracking rigs rarely brute-force blindly at first. They run enormous dictionaries through transformation rule sets — thousands of canned mutations including capitalising the first letter, appending two digits or a year, and mapping a to @, s to $, o to 0, i to 1. Every substitution trick popularised by office posters exists somewhere as a one-line rule in those sets. That is why P@ssw0rd! falls almost instantly despite passing every complexity checkbox: measured against a modern attack, its effective search space shrinks to millions of guesses rather than billions. Substitution applies a predictable function to a known word, and predictable functions cost attackers essentially nothing. Only genuine randomness expands the search space, because randomness is the one thing no rule set can shortcut.
Reuse is the real killer
The strongest password ever devised fails completely the day the site storing it suffers a breach. Criminal groups sit on billions of leaked email-and-password pairs and replay them against email providers, banking portals and shopping sites at industrial scale — a technique called credential stuffing. It keeps working because humans recycle: surveys repeatedly find that most people reuse passwords across many accounts. Your carefully crafted password for a forgotten 2013 forum seems harmless until that forum dumps its database, at which point the same string becomes a key tried against your primary email, your cloud storage, everything. Uniqueness is not perfectionism; it is containment. Unique passwords confine any single breach to the site that suffered it, while reuse lets one fire spread through your entire digital life.
Some illustrative numbers
Concrete comparisons make the arithmetic tangible. The figures below assume genuinely random selection from each pool; human-chosen patterns collapse these numbers dramatically, which is precisely the argument of this article.
| Pattern | Approximate entropy | Practical outlook |
|---|---|---|
| Eight random lowercase letters | About 37.6 bits | Within reach of serious offline cracking |
| Twelve random printable-keyboard characters | About 78.7 bits | Astronomically expensive to brute-force |
| Dictionary word plus substitutions, P@ssw0rd style | Far less than its length suggests | Falls quickly to common rule-based attacks |
| Six random words from a 7,776-word list | About 77.5 bits | Equally strong, far easier to remember |
Passphrases: long and memorable
If random gibberish guarantees a sticky note on the monitor, consider passphrases instead. The diceware method selects words by rolling dice against a 7,776-word list, where each word contributes roughly 12.9 bits of entropy — six words land near 78 bits, matching a twelve-character random password while staying typeable and memorable. Phrases built from unrelated nouns stick in memory because brains adore imagery, so users resent them less and reuse them less reluctantly. They also survive small typos gracefully on the first attempt, unlike symbol-laden strings that demand three tries and a password reset. The critical caveat is honest randomness: choosing personally meaningful or topically related words yourself collapses the entropy back toward dictionary scale, handing attackers an ordinary guessing game. Let a generator or physical dice do the selecting, and resist the urge to curate.
Password managers fix human memory
The reason reuse persists is cognitive load, not laziness: nobody can memorise forty unique random strings, so people improvise systems, and improvised systems are exactly what cracking rules exploit. A password manager holds one strong master passphrase and generates a distinct random password for every site, autofilling them so uniqueness costs nothing in daily use. The master passphrase is the one credential worth making long and memorable — a six-word passphrase fits perfectly here. As a bonus, managers refuse to autofill on lookalike phishing domains, quietly training you away from fakes that eyeballs miss. Adopting one converts account security from a permanent memory feat into a single decision made once. For most people, it is the highest-value security change available this week — ahead of every clever mnemonic ever suggested.
MFA beats complexity theatre
A twenty-character masterpiece still loses instantly to a convincing phishing page. Multi-factor authentication changes the economics of attack because the adversary now needs something a stolen database cannot contain: a rotating authenticator code, a hardware key tap, a platform passkey. Against credential stuffing and bulk phishing campaigns, MFA blocks the overwhelming majority of automated account takeovers regardless of password artistry. Where you have the choice, prefer authenticator apps or passkeys over SMS codes, which SIM-swap fraud can intercept mid-flight. Complexity rules guard the front door; MFA guards the lock itself. When time is scarce, spend it enabling MFA on your primary email first — that mailbox resets the passwords to everything else you own.
What actually moves the needle
If you retain only a summary, retain it ranked by real-world impact:
- Enable MFA everywhere it is offered — worth more than every other item combined.
- Install a password manager and let it generate unique credentials per site.
- Prefer length: sixteen-plus random characters or a six-word passphrase.
- Skip substitution gimmicks entirely; assume every trick is already automated.
- Never reuse a password across anything you would hate to lose.
Try the tools from this article
Free, no sign-up, and everything runs inside your browser — nothing is uploaded.