How to Make a Strong Password You Can Actually Remember
The best password is a long one you can actually remember, and in 2026 the easiest way to get there is a handful of random words. Most of the advice you've heard about symbols and capital letters is either out of date or makes passwords weaker in practice.
This guide covers what changed, how to build a password you can recall without a sticky note, and where it's smarter to stop memorizing altogether.
For years, sites told people to mix upper and lower case, add a number, throw in a symbol, and change it every ninety days. People did exactly that, and the result was predictable: "Summer2025!" in March, "Summer2026!" the next year. Attackers know every one of these habits, and their tools try them first.
The official guidance has moved on. NIST's current password guidelines (SP 800-63B-4, finalized in 2025) tell services not to force composition rules or scheduled password changes, and to favor length instead. Several summaries of the document also report a minimum of 15 characters when a password is the only thing protecting an account. If you ever need to rely on the exact wording, read the NIST text itself, because secondary guides don't all agree on the details.
The takeaway is simple. A long, unpredictable password beats a short, complicated one.
Every extra random character multiplies the number of guesses an attacker needs. That's why a short password with clever substitutions loses to a longer plain one.
Here is what a few random words are worth. These figures use the EFF's list of 7,776 words, where each randomly picked word adds about 12.9 bits of strength:
For comparison, 8 fully random characters drawn from letters, numbers and symbols land at roughly 50 bits. So four random words are about as strong as a messy eight-character password, and a lot easier to hold in your head. Six words is a comfortable choice for anything you really care about.
One condition matters more than everything else here: the words have to be picked at random. A line from a song, a movie quote, or "my dog Rex loves the beach" does not count, because people choose phrases that are far more predictable than they feel.
1. Get random words. For each word, roll five dice and look up the number in the EFF word list, then repeat for as many words as you need. A generator that uses a proper random source does the same job. Don't pick the words yourself.
2. Use five or six words. Put a space or a hyphen between them. Spaces are fine on most modern sites.
3. Make a picture. Turn the words into a short, slightly ridiculous scene in your mind. "Ladder, pickle, orbit, velvet, canyon" is easier to keep if you picture a pickle climbing a ladder over a velvet canyon. (Don't use that one, though. It's published now.)
4. Type it ten times. Muscle memory does most of the work. Repeat it on three different days and it will stick.
5. Use it once. One passphrase, one job.
If you want a quick random string instead, our password generator runs entirely in your browser and has length presets. It also has an optional field that starts from a name or word. That's convenient, but treat it as a compromise: only the random part adds strength, so for anything important use a fully random result.
- Names, birthdays, pets, teams, or anything someone could find on your social profiles.
- Keyboard patterns like "qwerty" or "1qaz2wsx".
- A common word plus a number plus a symbol on the end.
- Swapping "a" for "@" and "o" for "0". Cracking tools try those swaps automatically.
- The same password on two sites, even a strong one. If one service leaks it, attackers try it everywhere else.
That last point is probably the most important. Plenty of surveys put the share of people who reuse passwords at somewhere between half and two thirds, and reuse is what turns one small breach into several hacked accounts.
A memorable passphrase is for the few passwords you can't avoid typing from memory: your password manager's master password, your device login, and probably your main email account. Everything else should live in a password manager and be generated at random, long and unique.
Surveys put regular password manager use at roughly a third of adults, so most people are still relying on memory, browser storage or paper. A manager built into your browser or phone is a big step up from reusing a password, and a dedicated one adds features like sharing and breach alerts.
Passkeys are worth turning on wherever a site offers them. They replace the password with something tied to your device, so there is nothing to phish or reuse. You'll still need passwords for a while, because many sites don't support passkeys yet.
Even a great password can leak through a data breach or a phishing page. Two-step verification covers that gap. An authenticator app or a hardware key is better than text messages, though any second step beats none. Turn it on first for your email, since a hacked inbox lets someone reset everything else.
- Use a long password, at least 12 characters, and 16 or more for important accounts.
- Pick words at random instead of choosing a phrase yourself.
- Never reuse a password.
- Keep a password manager for everything you don't memorize.
- Turn on two-step verification, starting with email.
- Change a password when you have a reason, such as a breach notice, not on a timer.
Is a whole sentence a good password? Length helps, but a sentence you wrote yourself is much more predictable than random words, so it's weaker than it looks.
How often should I change my passwords? Only when there's a reason: a breach notice, a lost device, or a suspicious login. Regular scheduled changes mostly lead to weaker passwords.
Are spaces allowed? NIST's guidance says services should accept them, and many do. If a site rejects spaces, use hyphens instead.
Is it safe to use an online generator? It's safest when the page works entirely in your browser and sends nothing to a server. For your most sensitive accounts, use your password manager's built-in generator.
- NIST Special Publication 800-63B: https://pages.nist.gov/800-63-4/sp800-63b.html
- NIST password guidelines explained (Netwrix): https://netwrix.com/en/resources/blog/nist-password-guidelines/
- EFF's wordlists for random passphrases: https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases
- The Diceware Passphrase FAQ: https://theworld.com/~reinhold/dicewarefaq.html
- Password manager statistics 2026: https://sqmagazine.co.uk/password-manager-statistics/
This guide covers what changed, how to build a password you can recall without a sticky note, and where it's smarter to stop memorizing altogether.
Why the old password rules backfired
For years, sites told people to mix upper and lower case, add a number, throw in a symbol, and change it every ninety days. People did exactly that, and the result was predictable: "Summer2025!" in March, "Summer2026!" the next year. Attackers know every one of these habits, and their tools try them first.
The official guidance has moved on. NIST's current password guidelines (SP 800-63B-4, finalized in 2025) tell services not to force composition rules or scheduled password changes, and to favor length instead. Several summaries of the document also report a minimum of 15 characters when a password is the only thing protecting an account. If you ever need to rely on the exact wording, read the NIST text itself, because secondary guides don't all agree on the details.
The takeaway is simple. A long, unpredictable password beats a short, complicated one.
Length is the cheap win
Every extra random character multiplies the number of guesses an attacker needs. That's why a short password with clever substitutions loses to a longer plain one.
Here is what a few random words are worth. These figures use the EFF's list of 7,776 words, where each randomly picked word adds about 12.9 bits of strength:
| Words in the passphrase | Approximate strength |
|---|---|
| 4 words | about 52 bits |
| 5 words | about 65 bits |
| 6 words | about 77 bits |
| 7 words | about 90 bits |
For comparison, 8 fully random characters drawn from letters, numbers and symbols land at roughly 50 bits. So four random words are about as strong as a messy eight-character password, and a lot easier to hold in your head. Six words is a comfortable choice for anything you really care about.
One condition matters more than everything else here: the words have to be picked at random. A line from a song, a movie quote, or "my dog Rex loves the beach" does not count, because people choose phrases that are far more predictable than they feel.
How to build one in two minutes
1. Get random words. For each word, roll five dice and look up the number in the EFF word list, then repeat for as many words as you need. A generator that uses a proper random source does the same job. Don't pick the words yourself.
2. Use five or six words. Put a space or a hyphen between them. Spaces are fine on most modern sites.
3. Make a picture. Turn the words into a short, slightly ridiculous scene in your mind. "Ladder, pickle, orbit, velvet, canyon" is easier to keep if you picture a pickle climbing a ladder over a velvet canyon. (Don't use that one, though. It's published now.)
4. Type it ten times. Muscle memory does most of the work. Repeat it on three different days and it will stick.
5. Use it once. One passphrase, one job.
If you want a quick random string instead, our password generator runs entirely in your browser and has length presets. It also has an optional field that starts from a name or word. That's convenient, but treat it as a compromise: only the random part adds strength, so for anything important use a fully random result.
What to avoid
- Names, birthdays, pets, teams, or anything someone could find on your social profiles.
- Keyboard patterns like "qwerty" or "1qaz2wsx".
- A common word plus a number plus a symbol on the end.
- Swapping "a" for "@" and "o" for "0". Cracking tools try those swaps automatically.
- The same password on two sites, even a strong one. If one service leaks it, attackers try it everywhere else.
That last point is probably the most important. Plenty of surveys put the share of people who reuse passwords at somewhere between half and two thirds, and reuse is what turns one small breach into several hacked accounts.
You shouldn't memorize most of them
A memorable passphrase is for the few passwords you can't avoid typing from memory: your password manager's master password, your device login, and probably your main email account. Everything else should live in a password manager and be generated at random, long and unique.
Surveys put regular password manager use at roughly a third of adults, so most people are still relying on memory, browser storage or paper. A manager built into your browser or phone is a big step up from reusing a password, and a dedicated one adds features like sharing and breach alerts.
Passkeys are worth turning on wherever a site offers them. They replace the password with something tied to your device, so there is nothing to phish or reuse. You'll still need passwords for a while, because many sites don't support passkeys yet.
Add a second step
Even a great password can leak through a data breach or a phishing page. Two-step verification covers that gap. An authenticator app or a hardware key is better than text messages, though any second step beats none. Turn it on first for your email, since a hacked inbox lets someone reset everything else.
A short checklist
- Use a long password, at least 12 characters, and 16 or more for important accounts.
- Pick words at random instead of choosing a phrase yourself.
- Never reuse a password.
- Keep a password manager for everything you don't memorize.
- Turn on two-step verification, starting with email.
- Change a password when you have a reason, such as a breach notice, not on a timer.
Common questions
Is a whole sentence a good password? Length helps, but a sentence you wrote yourself is much more predictable than random words, so it's weaker than it looks.
How often should I change my passwords? Only when there's a reason: a breach notice, a lost device, or a suspicious login. Regular scheduled changes mostly lead to weaker passwords.
Are spaces allowed? NIST's guidance says services should accept them, and many do. If a site rejects spaces, use hyphens instead.
Is it safe to use an online generator? It's safest when the page works entirely in your browser and sends nothing to a server. For your most sensitive accounts, use your password manager's built-in generator.
Sources
- NIST Special Publication 800-63B: https://pages.nist.gov/800-63-4/sp800-63b.html
- NIST password guidelines explained (Netwrix): https://netwrix.com/en/resources/blog/nist-password-guidelines/
- EFF's wordlists for random passphrases: https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases
- The Diceware Passphrase FAQ: https://theworld.com/~reinhold/dicewarefaq.html
- Password manager statistics 2026: https://sqmagazine.co.uk/password-manager-statistics/