Crafting a Good Password: 2026 Rules That Work

Crafting a Good Password in 2026: What Actually Works

By First published February 26, 2026 · Updated October 7, 2026 ≈15 min read

Crafting a good password comes down to three words: long, random, unique. The old "one capital, one number, one symbol" rule no longer cuts it. The newest U.S. standard from NIST asks for at least 15 characters. Length wins. Randomness wins. Reuse loses.

Illustration of a person at a computer late at night crafting a good password

The quick verdict: Let a password manager create a random 16+ character password for every account. Memorize one strong 6–7 word passphrase to lock the manager. Turn on passkeys or two-step login wherever you can.

Our score for this method: 9.4 / 10. It's free or cheap, works on every device, and beats every "clever" trick out there.

Introduction: Why Crafting a Good Password Still Matters

In today's digital world, a strong password is your first line of defense. It stands between hackers and your email, your bank and your work tools. And attackers know it.

In the Verizon 2025 Data Breach Investigations Report, stolen or abused logins were the top way attackers got in. They kicked off 22% of breaches. In basic web app attacks, stolen credentials showed up in 88% of cases. If you want the bigger picture, see our guide to the real dangers of hacking.

This guide is for anyone with an online account. You don't need to be technical. That's the whole point of Non-Developers. You just need a plan you'll actually follow.

Key takeaways

  • Make every password long (15–16+ characters), random and unique.
  • Skip personal info, common words and simple patterns like qwerty.
  • Use a password generator. Humans are bad at being random.
  • Store everything in a password manager.
  • Change a password when it leaks, not on a calendar. (This is new. More below.)

Who this guide is for

  • People who reuse one or two passwords "with small changes."
  • Families sharing logins for streaming and shopping.
  • Small teams and IT leads updating a password policy to match NIST.

How we put this together

We first published this guide in February 2026. For this update, we checked every tip against four public sources: NIST's August 2025 rules, CISA's "Secure Our World" advice, Hive Systems' yearly crack-time tables, and breach data from Verizon and NordPass. We also did the keyspace math ourselves, so you can check every number.

Method Overview: The 2026 Rules for a Strong Password

Think of this like a product spec sheet. Here's what you get when you follow modern password guidance.

15+
Minimum characters when a password is the only login factor
16+
Characters CISA tells everyday users to aim for
22%
Breaches that started with credential abuse
~3B
Passkeys in use worldwide

Key specs that matter

Tap each rule to see the details.

Length: 15 characters minimum (8 only with MFA)

NIST SP 800-63B Revision 4 came out in August 2025. If a password is the only thing guarding an account, services must require at least 15 characters. If it's one part of multi-factor login, the floor is 8. Services should allow at least 64 characters.

Composition: no forced "symbol + number" rules

NIST says services should not force mixes of character types. Why? People respond with predictable tricks, like Password1!. That pattern is in every cracking list.

Expiry: no forced changes every 90 days

Services shouldn't make you change passwords on a schedule. You change one when there's proof it leaked. Forced rotation leads to Summer2026! becoming Fall2026!.

Blocklists: check against breached passwords

Services should reject passwords found in breach lists, dictionaries and obvious patterns. Have I Been Pwned's Pwned Passwords is the best-known free list. In 2025 alone it added 244 million new leaked passwords from one Telegram dump.

Characters: spaces, emoji and Unicode allowed

NIST wants services to accept all printable ASCII characters, spaces and Unicode. That makes real sentences and passphrases possible.

No hints, no security questions

Password hints and "What's your pet's name?" questions shouldn't be used. That info is often on social media.

Price and value

The method itself is free. The tool that makes it easy, a password manager, costs $0 to about $48 a year. Bitwarden's free tier covers unlimited passwords. Apple Passwords and Google Password Manager come built into your phone. Paid plans add file storage, family sharing and breach alerts.

Anatomy of a Good Password: The Elements of a Strong Password

Here's the core idea in one picture. Each extra character multiplies the number of guesses an attacker needs. Adding length does far more than adding a symbol.

Diagram: crafting a good password with length, randomness and uniqueness Three pillars of a strong password. Length multiplies guesses. Randomness defeats pattern attacks. Uniqueness stops credential stuffing. LONG RANDOM UNIQUE 15–16+ characters or 6–7 random words Each character ×94 Each dice word ×7,776 Picked by dice or a password generator No names, dates, lyrics or keyboard walks One password per account A leak at one site can't unlock the rest Beats brute force Beats dictionary attacks Beats credential stuffing
The three pillars of crafting a good password. Miss any one and the other two can't save you.

The elements, updated for 2026

Our February guide listed four elements. They still hold, with two upgrades.

ElementWhat we said in FebruaryWhat to do now
LengthMinimum of 12 characters15+ characters minimum (NIST); 16+ is better (CISA)
UniquenessNever reuse a password across accountsSame. This is still the #1 rule.
ComplexityMix numbers, symbols, upper and lower caseNice to have. Randomness matters more than character types.
No personal infoNo name, birthday or easy-to-find detailsSame. Also skip pet names, sports teams and song lyrics.

What "strong" looks like

  • Weak: password123. Short, and a common pattern.
  • Looks strong, isn't: P@55w0rd!23. Our February guide used this as a good example. We were wrong. Swapping letters for look-alike numbers ("leetspeak") is one of the first tricks cracking tools try.
  • Strong and memorable: gravel-pumpkin-oyster-velcro-thirsty-lantern. Six random words.
  • Strongest (for a manager to remember): q7$Lm!vR2#zT9pXw. 16 random characters.

Don't use any example on this page as your real password. Once a password is published anywhere, it's burned.

How well it holds up over time

Cracking hardware gets faster every year. A good long password holds up. A short one keeps losing ground. The data below shows how fast.

Strength Analysis: How Long Would It Take to Crack?

Core use case: stopping guesses

Attackers rarely sit at a login page typing guesses. They steal a database of scrambled ("hashed") passwords. Then they guess offline, billions of times, on graphics cards. Curious how that scrambling works? Read how to encrypt your passwords securely.

Hive Systems tests this every year with high-end Nvidia RTX GPUs against bcrypt hashing. Look at how fast the same 8-character password is falling:

Years to crack an 8-character password using numbers, upper- and lowercase letters and symbols (bcrypt, consumer RTX GPUs). Source: Hive Systems Password Tables 2024–2026.

132 years sounds safe. It isn't. That's for one rig against a slow hash. Hive's 2025 table found an 8-character lowercase password falls in about 3 weeks. Hive also estimated AI-class hardware could be over a billion percent faster than its consumer setup. And the math only applies if the password is truly random. A reused or common password is cracked instantly, whatever its length.

The real metric: entropy (guessing difficulty)

"Entropy" is a fancy word for how many guesses it takes, measured in bits. Each extra bit doubles the work. Here's the math for random passwords and dice-picked passphrases:

Entropy in bits, assuming truly random picks. Random characters use the 94 printable ASCII symbols (6.55 bits each). Passphrase words come from the EFF 7,776-word list (12.9 bits each). Our calculation.

Two things jump out. A 6-word passphrase (77.5 bits) roughly matches a 12-character random password (78.7 bits). And a 16-character random password (104.9 bits) is in a different league. Every 10 extra bits means about 1,000 times more guessing.

Key performance categories

9.4
Overall score
Manager-generated passwords + passphrase master + passkeys/MFA. Editorial rating.
Brute-force resistance
9.8
Phishing resistance
8.5
Ease of daily use
9.2
Cost
9.7
Recovery if things go wrong
8.8

Brute-force resistance. Long random passwords are close to uncrackable with today's hardware. Phishing resistance. Managers only autofill on the real site, which helps. Passkeys are better still, since there's nothing to type into a fake page. Ease of use. Once set up, autofill is faster than typing.

Try it: private password strength checker

Start typing to see a rough estimate.
This is a rough guide. It can't tell whether you picked words randomly. Test a similar pattern, not your real password.

User Experience: Living With Strong Passwords

Setup: your first 30 minutes

  1. Pick a password manager. Bitwarden, 1Password, Apple Passwords or Google Password Manager are all solid starts. See our top password manager picks for a full comparison.
  2. Create a master passphrase. Roll dice with the EFF dice method, or use your manager's passphrase generator. Aim for 6–7 words.
  3. Write it down once and keep the paper somewhere safe at home. Forgetting it is the bigger risk for most people.
  4. Turn on two-step login for the manager and your email.
  5. Fix your top 5 accounts first: email, bank, phone carrier, cloud storage, work.

Daily use

When you sign up somewhere, click "generate." Let the manager save it. Next time, it fills in for you. You never see or type the password. That's the biggest win: no more mistyping, and it works across your laptop, phone and tablet.

Learning curve

Most people get comfortable in about a week. The hardest part is the first import. After that, it's mostly invisible.

Interface and controls

Every major manager has a browser extension and a phone app. Look for a "watchtower" or "password health" screen. It flags reused, weak and leaked passwords so you know what to fix next.

Password recovery and resetting

Sooner or later you'll need to reset something. Do it safely:

  1. Use the official site or app. Type the address yourself. Never reset through a link in a surprise email. That's how phishing works.
  2. Verify your identity with a recovery email, phone number or authenticator app, not easy-to-guess security questions.
  3. Create a brand-new password. Let the generator make it. Never reuse an old one.
  4. Update any account that shared that password. If one is compromised, the others are next.

Think you've already been breached? Follow our step-by-step guide on what to do when you've been hacked.

Comparative Analysis: Password Methods Head to Head

Here's how the common ways of crafting a password stack up.

MethodExample lengthEntropy (random)Easy to remember?Phishing-proof?CostOur take
"Complex" 8-char (P@ssw0rd style)8≤52 bits, far less in practiceYesNoFreeAvoid. Patterns are guessed first.
Personal sentence / song lyric20–40Unknown; low if quotedYesNoFreeRisky. Famous phrases are in wordlists.
Dice passphrase (6–7 words)35–5077–90 bitsYesNoFreeBest for the few you must memorize.
Manager-generated random16–20+105–131 bitsNo (manager does it)Partly (autofill checks site)$0–$48/yrBest for every account.
Passkeyn/aPublic-key cryptoNothing to rememberYesFreeUse wherever offered.

Password manager options and prices

ToolFree planPaid price (Oct 2026)Stands out for
BitwardenYes, unlimited passwordsPremium $19.80/yr (raised from $9.99 in Jan 2026)Open source; self-hosting option
1PasswordNo (trial only)Individual $3.99/mo, $47.88/yr (raised Mar 2026)Polished apps, Watchtower, Travel Mode
Sticky PasswordYesSee vendor siteAutofill across devices; local or cloud sync
Apple PasswordsBuilt inFreeSeamless on iPhone/Mac
Google Password ManagerBuilt inFreeSeamless in Chrome/Android

Bitwarden and 1Password prices from the vendors' 2026 announcements as reported by 9to5Mac and CostBench. Check the vendor's site before you buy.

When to choose which

  • All Apple or all Google household? The built-in manager is fine and free.
  • Mixed devices, Windows + iPhone? Pick a cross-platform tool like Bitwarden, 1Password or Sticky Password.
  • Small business? Use a business plan with shared vaults and admin recovery.

How does Sticky Password make login easier and more secure?

Sticky Password is a good example of what a manager does for you. It fills in and encrypts your logins across devices, so you don't carry dozens of passwords in your head. Read our full take on easy login with Sticky Password.

Pros and Cons of Long, Random, Unique Passwords

What we loved

✔ Near-uncrackable by brute force

16 random characters is about 105 bits. That's out of reach for today's GPU rigs.

✔ Stops credential stuffing cold

Unique passwords mean one leaked site can't unlock your others. That's how the 2023 23andMe breach spread: passwords reused from other leaks.

✔ Only one thing to memorize

Your master passphrase. Everything else is stored and autofilled for you.

✔ Matches NIST and CISA

Great for teams that need a policy they can defend in an audit.

Areas for improvement

✘ Single point of failure

Lose the master passphrase with no recovery set up, and you may lose everything. Set up an emergency kit or recovery contact.

✘ Doesn't stop social engineering

A perfect password typed into a fake site is still stolen. And attackers can skip passwords altogether by tricking a help desk, as in the 2023 MGM attack. Read who hacked MGM for that story. Add MFA or passkeys.

✘ Some sites still have old rules

You'll still hit "max 12 characters" or "must include a symbol." Adjust the generator settings when that happens.

✘ Paid plans got pricier in 2026

Both Bitwarden and 1Password raised prices this year. Free options still exist.

How Password Advice Evolved (and What's Next)

What changed since our February 2026 guide

Our first version of this guide recommended 12 characters and changing passwords every three to six months. That was common advice for years. But it's now out of date.

Do (2026)Don't
Use 15–16+ characters, or 6–7 random wordsRely on password123-style patterns or leetspeak
Enable two-factor login or passkeysShare passwords over text or email
Change a password right away after a breachChange every 3–6 months on a schedule "just because"
Use a unique password for every accountReuse the same password anywhere

Why drop scheduled changes? NIST found that forced rotation makes people choose weaker, predictable passwords. A strong, unique password that hasn't leaked doesn't need replacing. A leaked one needs replacing today.

What changed in 2025–2026

  • Crack times keep dropping. Hive's 8-character benchmark fell from 225 years (2024) to 132 years (2026).
  • Breach lists grew. Have I Been Pwned added hundreds of millions of leaked passwords from info-stealer malware dumps.
  • Prices rose. Bitwarden Premium doubled; 1Password added $12 a year.

The roadmap: passkeys

Passkeys replace the password with a key pair stored on your device. According to the FIDO Alliance 2025 Passkey Index, 93% of accounts at participating companies can use passkeys, 36% have one, and 26% of sign-ins use them. Passkey sign-ins succeed 93% of the time, more than double other methods. Passwords won't vanish soon, but they're becoming the backup, not the main lock.

Recommendations: Best Password Strategy for You

Best for

  • Anyone with more than 10 accounts
  • Families sharing logins
  • Small teams needing a NIST-aligned policy

Skip a manager if

  • You truly have only 2–3 accounts
  • Your employer bans third-party tools (use their approved one)
  • You won't set up any recovery option

Alternatives

  • Passkeys for any site that supports them
  • Hardware keys (FIDO2) for high-risk accounts
  • Dice passphrases + paper notebook kept at home, if you distrust software

Where to Get a Password Manager

Best deals and current pricing

Go straight to the vendor. Avoid "lifetime deal" resellers you don't know.

What to watch for

Discounts often show up around World Password Day (first Thursday in May), Black Friday and Cybersecurity Awareness Month (October). Price changes for existing customers usually kick in at renewal, so check your renewal date.

Final Verdict on Crafting a Good Password

Score: 9.4 / 10

It loses a few points only because the vault becomes one point of failure, and it doesn't fully stop phishing on its own.

  • Length beats complexity. Aim for 16+ characters.
  • Randomness beats cleverness. Let dice or a generator choose.
  • Uniqueness beats everything. Never reuse.
  • Pair it with MFA or passkeys.

Bottom line: Spend 30 minutes this week setting up a password manager. Lock it with a 6–7 word dice passphrase. Fix your email password first. You'll be safer than most people online.

Evidence and Proof

Videos

Want to see it explained? These four videos cover choosing, cracking, Diceware and passkeys. Each one plays here or opens on YouTube.

Computerphile: Dr. Mike Pound on how to choose a password.
▶ Watch on YouTube
Computerphile: how password cracking actually works.
▶ Watch on YouTube
Computerphile: picking a memorable but truly random passphrase with Diceware.
▶ Watch on YouTube
Google Chrome: a quick intro to passkeys.
▶ Watch on YouTube

Data: what the breach lists show

Our February guide listed the classics: 123456, password, qwerty and admin. NordPass's 2025 study confirms they're still everywhere. It looked at leaked passwords from September 2024 to September 2025 across 44 countries.

Rank (global, 2025)PasswordTimes found
1123456≈21.6 million
2admin≈21.0 million
312345678≈8.3 million
4123456789≈5.7 million
512345≈4.0 million
6password≈3.5 million
7Aa123456≈2.5 million
9Pass@123≈1.2 million

In the U.S., admin took first place. Notice Aa123456 and Pass@123. They tick every "complexity" box, and they're still in the top 10. Meeting a symbol rule doesn't make a password strong.

Case studies

Colonial Pipeline (2021): Attackers got in through an old VPN account that had no multi-factor login. The password had appeared in a leak. The result was a fuel supply shutdown along the U.S. East Coast.

23andMe (2023): Attackers used passwords leaked from other sites ("credential stuffing"). Because people reused passwords, data tied to about 6.9 million users was exposed.

What real users are saying (last 12 months)

We read recent Hacker News threads about password managers and passkeys. Here's what people reported, summarized with links to the original comments:

Sets their password manager to generate 16-character random passwords by default. They call it the sweet spot for U.S. sites and say they rarely hit one that rejects it.

— tatersolid, Hacker News, Oct 3, 2026 · view comment

Sites with strict symbol rules and forced resets (Ticketmaster was named) used to be a regular headache. Once they finally started using a password manager, it stopped being an issue.

— cyode, Hacker News, Oct 2, 2026 · view comment

Found that a few key financial sites break when you use generated passwords over 20 characters. Some even set different limits for their app and their website.

— bogometer, Hacker News, Oct 2, 2026 · view comment

Registers several passkeys per account, one in Bitwarden and one in the phone's built-in passkey store, so losing one doesn't lock them out.

— qlte, Hacker News, Sep 19, 2026 · view comment

Their dad shared his password manager master password with them as part of family planning, and also keeps their mom's key passwords in it. That's a smart recovery plan most families skip.

— apothegm, Hacker News, Sep 18, 2026 · view comment

A frustration: sites that support passkeys keep prompting them to save a new passkey at every login, across Chrome-based browsers.

— sitzkrieg, Hacker News, Sep 19, 2026 · view comment

Good Password FAQ

Why is crafting a strong password important?

Stolen logins were the #1 way attackers got in, per Verizon's 2025 report. A strong, unique password stops most guessing and credential-stuffing attacks before they start.

How long should a good password be in 2026?

At least 15 characters if it's the only thing protecting the account (NIST). CISA says 16. Longer is better.

How can I enhance the strength of my password?

Add length and randomness. A 16-character random password or a 6–7 word random passphrase beats a short password stuffed with symbols.

Should I use a password generator?

Yes. Humans are bad at being random. Use the generator built into a reputable password manager so the password is saved at the same time.

Should I change my passwords every 90 days?

No. Change one when there's a sign it leaked, like a breach notice. Scheduled changes push people toward weaker patterns.

Are passkeys better than passwords?

For most people, yes. They can't be phished or reused. Turn them on wherever you see the option.

How should I handle password recovery and resetting?

Only reset through the official site or app. Set up a recovery email, phone or emergency kit before you need it.

Sources

  1. NIST SP 800-63B-4, Digital Identity Guidelines: Authentication (Aug 2025)
  2. CISA: Use Strong Passwords
  3. Verizon 2025 Data Breach Investigations Report
  4. Hive Systems: Are Your Passwords in the Green? (2026 table) and 2025 table release
  5. NordPass: Top 200 Most Common Passwords (2025)
  6. EFF: New Wordlists for Random Passphrases
  7. FIDO Alliance: Passkey Index 2025
  8. Troy Hunt / Have I Been Pwned
  9. 9to5Mac: 1Password price increase (Feb 2026)
  10. xkcd #936: Password Strength

Related Posts

AI Development

How to Lead AI Development in 2026: 10 Evidence-Based Practices That Turn Adoption Into ROI The AI Development Field GuideUpdated 6 Oct 2026 ·...

read more...