“All my passwords are the same.” “I use my birthday or my name.” Sound familiar?
When a password leaks, it can lead to hijacked email or social accounts and fraudulent credit card charges - damage that is hard to undo. In this article, we explain how to create strong passwords, with concrete requirements and step-by-step instructions.
Why strong passwords matter
According to Japan’s Ministry of Internal Affairs and Communications (MIC) security guidance, reusing passwords and using simple ones are major causes of unauthorized login incidents.
Weak passwords create these risks:
- They can be cracked quickly by brute-force attacks
- A password leaked from one service gets reused on others, leading to account takeovers
- Guessable information like names, birthdays and phone numbers is easily exploited
Note: The more critical the service - banking, email, social media - the stronger and more unique the password should be.
What makes a password strong
Based on guidance from the U.S. National Institute of Standards and Technology (NIST SP 800-63B) and MIC guidelines, here are the key requirements:
| Requirement | Guideline |
|---|---|
| Sufficient length | 12+ characters (14+ recommended for critical services) |
| Character variety | Combine uppercase, lowercase, digits and symbols |
| No reuse | Use a different password for every service |
| Not guessable | Avoid names, birthdays, phone numbers and dictionary words |
Length matters most
“Adding a symbol” matters far less than “making it longer”. The time needed to crack a password grows exponentially with its length.
- 8 characters, letters and digits only: can be cracked in hours to days
- 12 characters, mixed: billions of years of combinations
- 16+ characters: practically uncrackable
Key point: "Length" and "no reuse" affect real-world security far more than complexity alone.
How to create a strong password
Method 1: The passphrase approach (memorable)
Combine several unrelated words to make a long password.
Combine 3-4 unrelated words
Choose words with no obvious connection that only you can recall, like "river", "parachute" and "marmalade".
Mix in numbers and symbols
Add digits or symbols between words, such as "river2parachute!marmalade", to make it stronger.
Add your own private rule
Append a word nobody else could guess to make it harder to predict.
Method 2: Use a generator (most reliable)
Passwords you think up yourself tend to be guessable. Randomly generated passwords carry the lowest risk of being guessed.
Generate a password for free
The Tools Hub password generator creates secure passwords with cryptographically secure randomness in seconds. Generated passwords are never sent to any server.
How to use it (3 steps)
Set length and character types
We recommend 16+ characters with uppercase, lowercase, digits and symbols all enabled.
Generate and check the strength
Click generate to see a random password with a strength indicator showing how secure it is.
Copy and use it
Copy the password to your clipboard and paste it into each service's sign-up page.
Tool mentioned in this article
Password Generator
Generate secure passwords for free with cryptographic randomness. Runs entirely in your browser.
Managing the passwords you generate
Random passwords are hard to memorize, which is why we strongly recommend a password manager.
- Save generated passwords in your password manager
- Combine it with your browser’s autofill
- Manage just one strong master password
With a password manager, you can use long, unique passwords everywhere without having to remember them.
Extra security: Enable two-factor authentication (2FA) on critical services. Even if a password leaks, 2FA protects your account.
Summary
- Create passwords with 12+ characters mixing uppercase, lowercase, digits and symbols
- Never reuse passwords across services
- Never use names, birthdays or dictionary words
- Randomly generated passwords are the least guessable
- Manage them with a password manager
- Add two-factor authentication on critical services
Reviewing your passwords is one of the cheapest and most effective security measures available. Start with your most important accounts and update them using the methods in this article.
FAQ
How many characters should a password have?
12 or more is recommended. For critical services like banking and email, aim for 14 or more.
What if I can’t remember my passwords?
Use a password manager. Store generated passwords there, and you only need to remember one master password.
Do I need to change passwords regularly?
Current guidance from MIC emphasizes “sufficient length” and “no reuse” over periodic changes. However, change immediately if a leak is suspected.
Where can I enable two-factor authentication?
Almost all major email, social, banking and cloud services offer 2FA. Enable it from each service’s security settings.