Skip to content
VaultPass

Passwords

How to create a secure password (and still remember it tomorrow)

The VaultPass desk5 min read
An ornate wrought-iron gothic lock plate with pierced tracery

Almost everything we were taught about secure passwords was wrong. The odd symbols, the change every three months, the compulsory capital at the start: none of it protected as much as one far duller thing, length.

When a website forces you to include “one capital, one number and one symbol”, it is applying a recipe written in 2003. Its author, an engineer at the American standards institute named Bill Burr, said years later that he regretted it: those rules made passwords harder for people to remember and barely harder for machines to break.

This article covers what actually works, why, and how to build a password you can sustain over time without losing your mind.

Why length beats complexity

An attacker trying to guess a password does not type it by hand. They use software that tries combinations at a speed that is hard to picture: on a consumer graphics card, billions of attempts per second against certain kinds of hashing.

Against that speed, every character you add does not add — it multiplies.

Think of it this way. If your password uses only lowercase letters, each position has 26 possibilities. Two positions are 26 × 26. Three are 26 × 26 × 26. Adding one letter multiplies the attacker’s work by 26. Adding capitals and digits to the alphabet helps too, but it only multiplies once: you go from 26 options per slot to about 62.

The arithmetic is blunt:

Password Composition Approximate combinations
house12 7 characters, letters and digits 1.5 trillion
House#2024 10 characters, “complex” 800 quadrillion
table pencil cloud thunder 4 random words Millions of times more than the row above

The third is easier to remember than the second and vastly harder to break. That is the whole idea.

The mistake that actually costs you: reuse

The entire conversation about strength becomes secondary next to a bigger problem. Most people do not lose an account because someone guessed their password. They lose it because that password already leaked somewhere else.

The attack is called credential stuffing and it is as simple as it sounds: some shop suffers a breach, a list of emails and passwords gets published, and an automated program tries those same pairs on Gmail, on Amazon, on your bank and on Instagram. There is nothing to guess. They already have the key.

So the rule with the best return is not “make complicated passwords”. It is:

A different password on every site. No exceptions on the accounts that matter.

If you make only one change after reading this, make it separating your email password from all the others. Email is the master key: whoever controls it can request a reset on almost any other account.

Three methods that work

1. Generate them at random and never learn them

This is the right option for 95% of your accounts. A generator produces something like 7vK$mQ2xLp9!wRt4 and you never memorise it: your password manager stores it and fills it in.

You can create one right now with the VaultPass generator, which uses the browser’s own cryptographic randomness and sends nothing to any server.

The usual objection is “what if the manager fails?”. It is a fair question with a fair answer: serious managers let you export your data and save a recovery code. Against that, the risk of reusing one key across forty sites is far larger and far more likely.

2. Phrases made of random words

For the passwords you genuinely have to type from memory — your manager’s master key, your laptop, your email — a phrase is the better idea.

The classic method is called Diceware: you pick words at random from a long list, traditionally by rolling dice. Five or six words give enormous security:

vinegar · stencil · rhombus · broom · ivory

It is long, it is strange, and your brain can still hold it after two or three days of use, because words hook onto images. x7#Kq2 hooks onto nothing.

What matters is that the words come out genuinely at random. If you choose them yourself, you will gravitate towards related ideas and build something far more predictable than you think. You can generate one with the passphrase tool.

3. The personal sentence method, carefully

Take a sentence you remember and keep the initials: “My first dog was called Trick and he chewed chairs” → Mfdwc7Tahcc. It works reasonably well provided the sentence is not a known quotation or something you have posted on social media. Song lyrics and proverbs do not qualify: lists of millions of them exist.

It is the weakest of the three methods, and it is still infinitely better than reusing.

What you can stop doing

Changing your password every three months. Official guidance, including from the very institute that popularised the rule, no longer recommends it. When you force someone to change every quarter, they do not produce better keys: they produce Summer2025!, then Autumn2025!. You change a password when there is a reason: a breach, a suspicion, a lost device.

Swapping letters for numbers. a for 4, e for 3, o for 0. Attack dictionaries apply those rules automatically. They add almost nothing.

Putting the symbol at the end. Nearly everyone who needs a symbol puts ! at the end and the capital at the start. Cracking software knows that too, and tries that shape first.

How to check whether yours holds

Before settling on a password, ask two questions:

  1. Is it unique? If you use it anywhere else, it is no longer secure, however long it is.
  2. Has it already appeared in a breach? You can check with the breach checker, which sends only the first five characters of a hash and never the password itself.

And if you want an estimate of what it would cost to break, the strength checker gives you one without the key leaving your browser.

The summary, in four lines

  • Length rules. Sixteen random characters, or five random words.
  • A different password per site, starting with email.
  • Let a machine generate them and a manager store them; you remember one.
  • Turn on two-factor authentication wherever you can. A stolen password stops being enough.

None of these steps requires understanding cryptography. They require doing it once, calmly, and never thinking about it again.

Frequently asked

The questions that keep coming up

How many characters should a secure password have?

For an ordinary account, 16 random characters are enough with plenty of margin. For a password manager's master key or your main email, aim for 20 or more, or a phrase of five or six random words.

Is a password with symbols better than a long phrase?

A long phrase of random words is usually more secure and far easier to remember than a short password full of symbols. Symbols only help once the password is already long.

Does swapping a letter for a number help, like writing P4ssw0rd?

No. The programs that try passwords have known every one of those substitutions for decades and apply them automatically. P4ssw0rd falls at practically the same speed as Password.

Can I write my passwords on paper?

For most people, yes, as long as that paper lives in your home and not in your bag or taped to the monitor. The real risk for almost everyone is remote attacks, not someone going through your drawers.

Keep reading