“All my passwords are the same.” “I use my birthday or my name.” Sound familiar?

When a password leaks, it can lead to hijacked email or social accounts and fraudulent credit card charges - damage that is hard to undo. In this article, we explain how to create strong passwords, with concrete requirements and step-by-step instructions.

Why strong passwords matter

According to Japan’s Ministry of Internal Affairs and Communications (MIC) security guidance, reusing passwords and using simple ones are major causes of unauthorized login incidents.

Weak passwords create these risks:

  • They can be cracked quickly by brute-force attacks
  • A password leaked from one service gets reused on others, leading to account takeovers
  • Guessable information like names, birthdays and phone numbers is easily exploited

Note: The more critical the service - banking, email, social media - the stronger and more unique the password should be.

What makes a password strong

Based on guidance from the U.S. National Institute of Standards and Technology (NIST SP 800-63B) and MIC guidelines, here are the key requirements:

Requirement Guideline
Sufficient length 12+ characters (14+ recommended for critical services)
Character variety Combine uppercase, lowercase, digits and symbols
No reuse Use a different password for every service
Not guessable Avoid names, birthdays, phone numbers and dictionary words

Length matters most

“Adding a symbol” matters far less than “making it longer”. The time needed to crack a password grows exponentially with its length.

  • 8 characters, letters and digits only: can be cracked in hours to days
  • 12 characters, mixed: billions of years of combinations
  • 16+ characters: practically uncrackable

Key point: "Length" and "no reuse" affect real-world security far more than complexity alone.

How to create a strong password

Method 1: The passphrase approach (memorable)

Combine several unrelated words to make a long password.

1

Combine 3-4 unrelated words

Choose words with no obvious connection that only you can recall, like "river", "parachute" and "marmalade".

2

Mix in numbers and symbols

Add digits or symbols between words, such as "river2parachute!marmalade", to make it stronger.

3

Add your own private rule

Append a word nobody else could guess to make it harder to predict.

Method 2: Use a generator (most reliable)

Passwords you think up yourself tend to be guessable. Randomly generated passwords carry the lowest risk of being guessed.

Generate a password for free

The Tools Hub password generator creates secure passwords with cryptographically secure randomness in seconds. Generated passwords are never sent to any server.

How to use it (3 steps)

1

Set length and character types

We recommend 16+ characters with uppercase, lowercase, digits and symbols all enabled.

2

Generate and check the strength

Click generate to see a random password with a strength indicator showing how secure it is.

3

Copy and use it

Copy the password to your clipboard and paste it into each service's sign-up page.

Tool mentioned in this article

Password Generator

Generate secure passwords for free with cryptographic randomness. Runs entirely in your browser.

Create a password

Managing the passwords you generate

Random passwords are hard to memorize, which is why we strongly recommend a password manager.

  • Save generated passwords in your password manager
  • Combine it with your browser’s autofill
  • Manage just one strong master password

With a password manager, you can use long, unique passwords everywhere without having to remember them.

Extra security: Enable two-factor authentication (2FA) on critical services. Even if a password leaks, 2FA protects your account.

Summary

  • Create passwords with 12+ characters mixing uppercase, lowercase, digits and symbols
  • Never reuse passwords across services
  • Never use names, birthdays or dictionary words
  • Randomly generated passwords are the least guessable
  • Manage them with a password manager
  • Add two-factor authentication on critical services

Reviewing your passwords is one of the cheapest and most effective security measures available. Start with your most important accounts and update them using the methods in this article.

FAQ

How many characters should a password have?

12 or more is recommended. For critical services like banking and email, aim for 14 or more.

What if I can’t remember my passwords?

Use a password manager. Store generated passwords there, and you only need to remember one master password.

Do I need to change passwords regularly?

Current guidance from MIC emphasizes “sufficient length” and “no reuse” over periodic changes. However, change immediately if a leak is suspected.

Where can I enable two-factor authentication?

Almost all major email, social, banking and cloud services offer 2FA. Enable it from each service’s security settings.