Weak, reused passwords are the number one way ordinary people get hacked. The good news: creating strong passwords is simple once you know a few rules — and you don’t have to memorise dozens of them. Here’s how.
Note: Informational content to help you improve your everyday security.
What makes a password strong
Three things matter, in order:
- Length — longer beats complex. A 16-character password is far stronger than an 8-character one full of symbols.
- Uniqueness — a different password for every account. This is the big one.
- Unpredictability — avoid names, birthdays, and common words attackers guess first.
A long, unique, random password is essentially impossible to crack by guessing.
The mistake almost everyone makes
Reusing the same password across sites. When one site gets breached (and they do, constantly), attackers take that email-and-password combo and try it everywhere else. One leak becomes ten hacked accounts. Check if this has happened to you in how to check if your password has been leaked.
The passphrase trick (easy to remember, hard to crack)
For the few passwords you must memorise, use a passphrase: four or five random, unrelated words strung together, like copper-lantern-turtle-mango. It’s long, easy to picture, and very hard to guess. Add a number or symbol if the site requires it.
The real solution: a password manager
You can’t memorise a unique 16-character password for 100 accounts — and you shouldn’t try. A password manager creates and stores strong, unique passwords for every site, and fills them in for you. You only remember one strong master passphrase.
It’s the single biggest upgrade to your security. We cover the options in best password managers.
Add a second lock: 2FA
Even a strong password is stronger with two-factor authentication (2FA) — a second step (like a code on your phone) that blocks logins even if your password leaks. Learn how in what is two-factor authentication.
Passwords to fix first
Not all accounts are equal. Prioritise unique, strong passwords on:
- Your email (it can reset everything else).
- Your bank and payment accounts.
- Anything with your card saved or personal data.
Conclusion
Strong passwords are long, unique, and unpredictable — and the sane way to manage them is a password manager plus one memorable master passphrase. Turn on 2FA for your most important accounts, and fix your email password first. Do that and you’ve closed the door on the most common way people get hacked.

Leave a Reply