Five Basic Tips for Choosing a Proper Password
Sep 9, 2026
Your password is the deadbolt on the front door of your digital life. Most people still pick locks a thief would laugh at. Here are five fundamentals that actually hold up.
Length beats complexity
A 16-character passphrase of ordinary words is dramatically harder to crack than an 8-character mess of symbols. Every extra character multiplies the attacker's work exponentially. Aim for at least 12–16 characters; length is the single biggest lever you control.
Use a passphrase, not a word
String together three or four unrelated words — 'correct-horse-battery-staple' style. It's easy to remember, easy to type, and far stronger than 'P@ssw0rd1!'. Avoid famous quotes or song lyrics; those are in every cracking dictionary.
Never reuse passwords
One breach should not unlock your email, bank, and every account you own. Use a reputable password manager to generate and store a unique password for every site. You only remember one strong master passphrase; the manager handles the rest.
Turn on multi-factor authentication
A strong password plus MFA stops the overwhelming majority of account takeovers. Even if your password leaks, the attacker still needs your phone or hardware key. Prefer an authenticator app or hardware key over SMS codes where possible.
Check if you've already been breached
Before choosing a new password, check it against a breach database like Have I Been Pwned. If a password you're considering has appeared in a known leak, it's burned — attackers try those first. If your current one is leaked, change it everywhere you used it.
None of this is exotic. The people who get hacked aren't usually defeated by genius attackers — they're defeated by 'password123' and reuse. Get these five right and you've already outpaced most of the internet.