Basics

How to create a strong password

“At least one capital letter, one number and one symbol” – rules like that lead to passwords such as “Summer2026!”, which attackers guess in seconds. What really makes a password strong is simpler: length, true randomness and a different one for every account. Here is how to get there.

Fastest way: the Password Generator creates a random password of the length you need – right in your browser, nothing is sent.

Generate a strong password

The short version

How long should a password be?

Current guidance from NIST (SP 800-63B) focuses on length instead of complicated composition rules: services should allow long passwords and passphrases, should not force arbitrary character requirements and should block known compromised passwords. Germany’s BSI says the same in simpler words: the longer, the better.

Why length matters so much becomes obvious with a little math. Every additional character multiplies the number of possibilities. For an attacker trying 10 billion passwords per second (realistic for a stolen database with weak hashing):

Random passwordPossibilitiesAverage time to crack
8 characters, all character typesabout 1015about 4 days
12 characters, all character typesabout 1023hundreds of thousands of years
16 characters, all character typesabout 1031practically uncrackable
20 characters, letters onlyabout 1034practically uncrackable
Passphrase of 6 words (4,096-word list)about 1021thousands of years

These numbers only hold for random passwords. A made-up 12-character password is often cracked in minutes – see below.

Why randomness beats symbols

Attackers don’t try every combination in order. They start with lists of leaked passwords, dictionaries, names and years – and apply the usual “tricks”: a capital first letter, a number and an exclamation mark at the end, “a” replaced by “@”. A password like Summer2026! passes every complexity rule and still falls within seconds.

A generator picks every character with true randomness – in the browser via crypto.getRandomValues, the same random source used for encryption. There is no pattern to exploit, so the math above actually applies.

Choose a length, pick character groups, copy – the generator also shows how long an attacker would need.

Common mistakes

MistakeWhy it’s dangerous
One password for several accountsWhen one service is breached, attackers automatically try the stolen credentials on email, shopping and payment sites (“credential stuffing”).
Names, birthdays, petsOften visible on social media and among the first guesses.
Word + year + symbolThe most common pattern of all, e.g. Chicago2026!.
Keyboard patternsqwerty, 123456 or asdfgh are on every attack list.
Small variationsPassword1 → Password2: whoever knows the old one guesses the new one.
Sending passwords by email or chatMessages are stored – often for years and on several devices.

Whether an existing password contains such patterns is shown by the password strength check – locally in your browser, without sending the password anywhere.

How am I supposed to remember it?

You don’t – at least not all of them. A password manager (e.g. Bitwarden, 1Password, KeePassXC or the one built into your browser and phone) stores any number of random passwords encrypted and fills them in automatically. You only need to remember one master password.

For that one password – and for anything you type by hand regularly, like your computer login – a passphrase is ideal: several random words that you can memorize after a few days and that are still very strong.

Beyond a good password

Generate a strong password

Random passwords with the length and rules you need, or memorable passphrases – with an honest strength meter. Free and local in your browser.

Frequently asked questions

How long should a strong password be?

At least 12 characters, and 16 or more for important accounts such as email and banking. A passphrase of 5 to 6 random words is also very strong.

Does a strong password need symbols?

No. Symbols increase the possibilities per character, but a longer password without symbols can be just as strong. What matters is that it is random.

Is an online password generator safe?

Yes, if the password is generated in your browser and never transmitted – like the Melon Tools Password Generator. It uses the browser’s cryptographic random number generator and stores nothing.

How often should I change my password?

Only when there is a reason – such as a data breach or a suspicion. Forced periodic changes usually lead to weaker passwords and are no longer recommended by NIST.

Can I use one password for several accounts?

No. When one service is breached, attackers automatically try the stolen credentials elsewhere. A password manager makes unique passwords easy.

Which is safer: password or passphrase?

Both are safe when randomly generated and long enough. Passwords are shorter and ideal for a password manager; passphrases are easier to remember and type.

Sources

  1. NIST Special Publication 800-63B – Digital Identity Guidelines: Authentication, National Institute of Standards and Technology.
  2. Sichere Passwörter erstellen, German Federal Office for Information Security (BSI, in German).
  3. Crypto.getRandomValues(), MDN Web Docs – the random number generator the password generator uses.

Generate strong passwords – free, local in your browser.

Open the tool