How to Create a Strong Password (Free Generator)
4 min read
Most accounts are not broken into by guessing - they are cracked by software trying billions of combinations, or breached when a reused password leaks from another site. The fix is a long, random, unique password for every account.
Here is what makes a password genuinely strong and how to generate a secure password for free.
Step by step
- 1Favor length over complexity
Length is the single biggest factor. A 16-character password is dramatically harder to crack than an 8-character one, even a clever one. Aim for at least 16 characters.
- 2Make it random, not a word
Real words, names, and dates are the first things attackers try. Open the Password Generator to get a truly random string instead.
- 3Mix character types
Include uppercase, lowercase, numbers, and symbols. Turn these options on in the generator to widen the pool of possibilities.
- 4Use a unique password per account
Never reuse passwords. If one site is breached, reuse lets attackers walk into your other accounts. Generate a fresh one for each.
- 5Store them in a password manager
You cannot memorize dozens of random passwords - and you should not try. Save them in a reputable password manager and only remember that one master password.
Tips
- Turn on two-factor authentication (2FA) wherever you can - even a strong password is better with a second factor.
- Long passphrases of several random words are strong and easier to type for the few passwords you must remember (like your password manager).
- Change a password immediately if a site reports a breach, and never reuse the old one.
Frequently asked questions
What makes a password strong?
Length and randomness. A long (16+ character) string of random letters, numbers, and symbols that is not a real word and is not reused anywhere is extremely hard to crack.
Is this password generator safe?
Yes. It generates passwords in your browser using your device, so the password is never sent over the internet or stored.
How long should a password be?
At least 16 characters for important accounts. Longer is stronger - each extra character multiplies the number of combinations an attacker must try.