Basics
How to create a strong password
“At least one capital letter, one number and one symbol” – rules like that lead to passwords such as “Summer2026!”, which attackers guess in seconds. What really makes a password strong is simpler: length, true randomness and a different one for every account. Here is how to get there.
Fastest way: the Password Generator creates a random password of the length you need – right in your browser, nothing is sent.
Generate a strong passwordThe short version
- Long: at least 12, better 16 characters – or a passphrase of 5–6 words.
- Random: created by a generator, not made up.
- Unique: a different password for every account.
- Stored in a password manager – and protected with two-factor sign-in wherever possible.
How long should a password be?
Current guidance from NIST (SP 800-63B) focuses on length instead of complicated composition rules: services should allow long passwords and passphrases, should not force arbitrary character requirements and should block known compromised passwords. Germany’s BSI says the same in simpler words: the longer, the better.
Why length matters so much becomes obvious with a little math. Every additional character multiplies the number of possibilities. For an attacker trying 10 billion passwords per second (realistic for a stolen database with weak hashing):
| Random password | Possibilities | Average time to crack |
|---|---|---|
| 8 characters, all character types | about 1015 | about 4 days |
| 12 characters, all character types | about 1023 | hundreds of thousands of years |
| 16 characters, all character types | about 1031 | practically uncrackable |
| 20 characters, letters only | about 1034 | practically uncrackable |
| Passphrase of 6 words (4,096-word list) | about 1021 | thousands of years |
These numbers only hold for random passwords. A made-up 12-character password is often cracked in minutes – see below.
Why randomness beats symbols
Attackers don’t try every combination in order. They start with lists of leaked passwords, dictionaries, names and years – and apply the usual “tricks”: a capital first letter, a number and an exclamation mark at the end, “a” replaced by “@”. A password like Summer2026! passes every complexity rule and still falls within seconds.
A generator picks every character with true randomness – in the browser via crypto.getRandomValues, the same random source used for encryption. There is no pattern to exploit, so the math above actually applies.
Choose a length, pick character groups, copy – the generator also shows how long an attacker would need.
Common mistakes
| Mistake | Why it’s dangerous |
|---|---|
| One password for several accounts | When one service is breached, attackers automatically try the stolen credentials on email, shopping and payment sites (“credential stuffing”). |
| Names, birthdays, pets | Often visible on social media and among the first guesses. |
| Word + year + symbol | The most common pattern of all, e.g. Chicago2026!. |
| Keyboard patterns | qwerty, 123456 or asdfgh are on every attack list. |
| Small variations | Password1 → Password2: whoever knows the old one guesses the new one. |
| Sending passwords by email or chat | Messages are stored – often for years and on several devices. |
Whether an existing password contains such patterns is shown by the password strength check – locally in your browser, without sending the password anywhere.
How am I supposed to remember it?
You don’t – at least not all of them. A password manager (e.g. Bitwarden, 1Password, KeePassXC or the one built into your browser and phone) stores any number of random passwords encrypted and fills them in automatically. You only need to remember one master password.
For that one password – and for anything you type by hand regularly, like your computer login – a passphrase is ideal: several random words that you can memorize after a few days and that are still very strong.
Beyond a good password
- Turn on two-factor authentication (2FA), especially for email, banking, cloud storage and social media. Then a password alone is no longer enough.
- Use passkeys where offered: they replace the password entirely and cannot be phished.
- Don’t change passwords on a schedule – NIST explicitly advises against forced periodic changes. Change a password when a service was breached or you suspect a problem.
- Protect your email account in particular: whoever controls it can reset the password of almost every other service.
Generate a strong password
Random passwords with the length and rules you need, or memorable passphrases – with an honest strength meter. Free and local in your browser.
Frequently asked questions
How long should a strong password be?
At least 12 characters, and 16 or more for important accounts such as email and banking. A passphrase of 5 to 6 random words is also very strong.
Does a strong password need symbols?
No. Symbols increase the possibilities per character, but a longer password without symbols can be just as strong. What matters is that it is random.
Is an online password generator safe?
Yes, if the password is generated in your browser and never transmitted – like the Melon Tools Password Generator. It uses the browser’s cryptographic random number generator and stores nothing.
How often should I change my password?
Only when there is a reason – such as a data breach or a suspicion. Forced periodic changes usually lead to weaker passwords and are no longer recommended by NIST.
Can I use one password for several accounts?
No. When one service is breached, attackers automatically try the stolen credentials elsewhere. A password manager makes unique passwords easy.
Which is safer: password or passphrase?
Both are safe when randomly generated and long enough. Passwords are shorter and ideal for a password manager; passphrases are easier to remember and type.
Sources
- NIST Special Publication 800-63B – Digital Identity Guidelines: Authentication, National Institute of Standards and Technology.
- Sichere Passwörter erstellen, German Federal Office for Information Security (BSI, in German).
- Crypto.getRandomValues(), MDN Web Docs – the random number generator the password generator uses.