Guide
What a secure password looks like in 2026
Most accounts aren't broken into by guessing. They're compromised because the same password leaked from another service. A strong password helps, but a unique password for every account and a second verification step help even more.
Length beats complexity
Every extra character multiplies the number of possible combinations. A random 16-character password is stronger than a 10-character one packed with symbols. The US standard NIST SP 800-63B recommends long passwords and screening against leaked passwords instead of required character types and forced periodic changes.
Passphrase
Something like “bike-cloud-owl-lamp-oats” is a passphrase: a few random words in a row. It's easy to remember and easy to type on a phone. The words have to be picked at random, not by you. A song lyric or a favorite quote is an easy target for an attacker.
Password manager
Remember one strong master password and let a password manager create and store the rest. It can also fill them in for you, and it spots phishing sites because it won't offer your password there. Password managers are built into browsers and phones, and they're also available as standalone apps.
Two-factor authentication
Turn on two-factor authentication for your email, bank, and work accounts. Even if your password leaks, an attacker can't sign in without the second step. Passkeys and authenticator apps are the most secure. SMS is weaker, but still better than nothing.