Guide · Security
Generating and Storing Strong Passwords Properly
Most password advice focuses on complexity: an uppercase letter, a digit, a symbol. That advice comes from an era when attackers guessed passwords one at a time over a network. Modern attacks take a stolen hash database and test billions of candidates per second on a GPU. Against that, length matters far more than complexity.
Entropy is the number that matters
Password strength is measured in bits of entropy, which is a function of how randomly the password was chosen and how large the pool it was chosen from was:
- 8 random lowercase letters: about 37 bits.
- 12 random characters from letters, digits and symbols: about 78 bits.
- 16 random characters from the same pool: about 104 bits.
- 5 randomly chosen dictionary words: about 64 bits, and far easier to type.
As a practical target, aim for at least 80 bits for anything that matters. A random 14-character password, or a five-word passphrase, clears that comfortably.
What does not work
- Substituting characters.
P@ssw0rdis not stronger thanpasswordin any meaningful sense — the substitution rules are the first thing cracking tools apply. - Appending a year or a site name. Credential-stuffing tools generate exactly these patterns.
- Reusing one strong password everywhere. One breach anywhere exposes every account. This is how most account takeovers actually happen.
- Periodic forced rotation. Changing a password every 90 days leads to predictable increments and weaker choices. Rotate on evidence of compromise instead.
Generating a password safely
Use a generator driven by a cryptographic random source. In a browser that is crypto.getRandomValues(); on the command line it is /dev/urandom, openssl rand or gpg --gen-random. Never use Math.random(), and never use a generator that derives its output from a date or a seed you can guess.
Our password generator uses the browser’s cryptographic API and runs locally, so the generated value is never transmitted, logged or stored anywhere.
One caveat about online generators in general: a page can only be trusted if the generation happens in the browser, which you can verify by watching the network tab. A generator that sends a request when you click “generate” may be receiving your password.
Storing dozens of credentials
Once you stop reusing passwords, you need somewhere to keep them. A reputable password manager is the answer. Look for:
- End-to-end encryption with a key derived from your master password, so the provider cannot read your vault.
- An audited, open or well-documented cryptographic design.
- A track record and a published security contact.
- Optional hardware-key or app-based second factor on the vault itself.
Keep an offline backup of the vault — an exported, encrypted copy on a physical device you control. Forgetting a master password with no backup means losing every credential at once.
Turn on a second factor
Even a perfect password can be phished. A second factor defeats it. In descending order of strength:
- Hardware security keys (FIDO2 / WebAuthn) — phishing-resistant, because the key checks the origin.
- Authenticator apps with time-based codes — strong, but still phishable if the user is tricked into entering the code on a fake page.
- SMS codes — better than nothing, but vulnerable to SIM swapping and interception.
Save the recovery codes when you enable a second factor, and store them somewhere other than the device that generates the codes.
A checklist
- One unique password per account, generated randomly, at least 14 characters.
- A password manager holding everything, protected by one long passphrase plus a second factor.
- Hardware keys on email, banking and cloud consoles.
- An encrypted offline backup of the vault.
- Rotate immediately if a service you use reports a breach.