In this guide
Tech 6 steps 25 min Easy

How to create a strong password and never get hacked

The practical method for creating long, unique passwords that are hard to guess, storing them in a password manager, turning on two-factor verification, and avoiding the scams that steal your accounts.

Updated
A person in a grey sweater types on a laptop at a wooden table, with a coffee mug and an open notebook beside them
Time 25 min
Difficulty Easy
You'll need A computer or phone · A password manager (free is enough) · Your phone to receive verification codes
6 steps

A weak password is the easiest link to break in any hack. Most accounts get compromised not because a genius hacker found a way in, but because of a short, predictable password reused across many sites. One single breach can put every account you own — starting with your email, which can reset the password of practically everything else — into the wrong hands.

This guide is not about memorizing a catchy password. It shows the process security-minded people actually use: understanding what really makes a password safe, dropping common and reused ones, letting a manager do the remembering, turning on two-factor verification, and learning to recognize attempts to trick you.

There is no “impossible to crack” password — there is one that becomes too expensive to crack relative to what it protects. Your goal is to make your account the hardest one on the list, not the hardest in the world.

Understand what actually makes a password strong

The classic mistake is thinking a strong password means a complicated one: P@ssw0rd!123. That is weak, because it is short and because attackers already know exactly which symbols and substitutions people use. What truly matters is length and unpredictability.

A 16-character password made of four or five unrelated words, like blender-sun-tooth-train, is far harder to crack than an 8-character one stuffed with symbols. Every extra character multiplies the number of combinations, and random words are just as hard to guess as random letters — but much easier to type.

The golden rule: length above all else. A random password generator, like the one built into the password manager you’ll use in step 3, produces unpredictable passwords automatically. You don’t have to invent anything.

Drop common and reused passwords

The most guessed passwords in the world are 123456, password, qwerty, and the classic your-name + birth-year. Lists with billions of leaked passwords feed attacks that test the most likely combinations against millions of accounts at once. If your password is on that list, you will be hacked without ever being a specific target.

Reuse is the second big danger. When a small site suffers a breach, attackers immediately try the same password on your email, bank, social networks, and shops. Anyone with a unique password per account doesn’t lose the rest of their digital life when one account falls.

The test is simple: if you use Christmas2024 for email, social media, your bank, and a streaming site, you don’t have four passwords — you have one password repeated four times. Each account needs its own unique password. That alone is the difference between losing one site and losing everything.

Use a password manager

The number one excuse for reusing a password is “how am I supposed to remember them all?”. The answer is: you don’t have to. A password manager (1Password, Bitwarden, Dashlane, or the one built into your browser) generates a unique random password for every account and keeps the whole set in an encrypted vault.

You only memorize one thing: your master password. It needs to be long and unique — never used anywhere else, never the same as any other account. The master password is the only one you hold in your head; everything else is generated randomly and filled in automatically.

Pick a reputable manager, turn on syncing (so you have your passwords on both phone and computer), and enable autofill. From then on, creating a new account is just letting the manager generate a 16–20 character password and saving it. Anyone who starts doing this never reuses a password again.

Turn on two-factor verification

A strong password is the first layer; two-factor verification (2FA) is the second. Even if your password is stolen from some breach, it alone won’t unlock the account — you also need a second factor the attacker doesn’t have.

The best method is an authenticator app (Google Authenticator, Microsoft Authenticator, Authy) or a physical security key, because codes are generated on your device and don’t rely on SMS. Prioritize the app or the key, and avoid SMS-based 2FA when you can, since your number can be hijacked through a SIM-swap scam.

Turn it on in order of importance: first your email (because it can reset every other account), then your bank and social networks. And store the recovery codes each service offers somewhere that isn’t your phone — if you switch devices without them, recovering your account can take days.

Learn not to get tricked

The strongest password in the world is useless if you type it into a fake site. The majority of compromised accounts today aren’t cracked — they’re taken through social engineering: emails and messages that mimic banks, couriers, and services asking you to click a link and “log in”.

Check the site address before typing your password: the domain must be exact (e.g. bank.com, not bank-secure.com). Be suspicious of urgency (“your account will be locked in 24 hours”) and of unsolicited messages with a link. Don’t type a password into a screen that arrived via an email or WhatsApp link; navigate to the site yourself using the address bar.

Final rule: default to suspicion. At the slightest sign of urgency, a pushy request, or an unexpected link, circle back to steps 3 and 4 — the manager only autofills the password on the right site, and 2FA will block most attacks even when a password does leak.

Review and update your passwords regularly

A strong password is not a one-time event: it loses strength over time, whether a service gets breached or you end up reusing the same one elsewhere. Set aside a moment, a few times a year, to review your most important accounts — email, bank, key social profiles — and change any password that is being reused or may be exposed.

While you’re at it, enable two-factor verification where it isn’t on yet and remove access from devices you don’t recognize. Keeping this short routine is what separates people who stay a step ahead from those who only react after something happens.

Common mistakes that make a password weak

  • Thinking symbols make a password strong. P@ssw0rd! has symbols and is weak; length matters more than decoration.
  • Reusing the same password. A breach on one small site takes down every account that shares that password.
  • Using personal data. Name, surname, birth date, your dog’s name, and your team are exactly what an attacker tries first.
  • Writing the password on a sticky note on the monitor. A manager’s encrypted vault, yes; a post-it on the screen, no.
  • Relying only on SMS two-factor. SIM-swap and interception attacks can take over your number and defeat it.
  • Not saving the recovery codes. Without them, switching devices can lock you out of your account for days.

After you protect your accounts

If your password was leaked, start today with email: change the password, turn on 2FA, and review which accounts share the same password — a manager shows this at a glance. Then schedule a semi-annual review: check the manager’s weak and reused password report, enable 2FA on accounts that still lack it, and change any password that shows up in a breach.

Security isn’t a one-time action, it’s a habit. That ten minutes every few months is what keeps your accounts off the easy-to-crack list.

Frequently asked questions

What is the minimum length for a password to be considered strong?

At least 12 characters; 16 is safer. Beyond that length, a passphrase of separated words is far stronger than a short password packed with symbols.

Is a password manager safe? Can I trust it?

Yes. It stores your passwords in an encrypted vault that only you unlock with a master password, and syncing between devices is encrypted too. The real risk is reusing passwords, not using a manager.

What is the difference between a strong password and two-factor verification?

A strong password stops it being guessed; two-factor verification stops a stolen password from being enough. They are different layers and you need both.

My password was leaked. What now?

Change it everywhere that uses the same password right away, starting with email and banking. A password manager flags which accounts use a leaked password, and a service like Have I Been Pwned confirms the breach.

#password#security#strong-password#password-manager#two-factor

Informational content. For risky situations or technical, legal or medical doubts, talk to a professional.

Keep going

Wi-Fi router on a high shelf in a bright living room with its antennas raised Tech

How to improve your home Wi-Fi signal

Improve Wi-Fi coverage with practical changes to router placement, frequency bands, channels, security, firmware, and carefully chosen extra equipment.

30 min Easy