Passwords: how to make them strong and keep track of them
Length, passphrases, password managers, reuse, rotation myths and leaked passwords. How to build passwords you can actually live with every day.
You almost certainly have more online accounts than you can remember, and most of them are protected by a small set of passwords with a number or an exclamation mark stuck on the end. That habit is what these pages are about: what genuinely makes a password hard to break, why the old advice about symbols and quarterly changes made things worse rather than better, and how to stop carrying any of it in your head.
Begin with what makes a password strong, because length does far more work than the punctuation rules a sign-up form pushes on you. If you want something you can still type from memory, four random words make a better passphrase than a clever substitution. The change that pays for itself fastest is moving everything into a password manager, and if you are wondering whether the one already built into your browser is enough, the honest comparison is here.
The expensive mistake in this area is reuse. One leaked shopping account becomes a way into your email, and your email is the reset button for everything else, which is why a single repeated password costs so much.
Articles in this hub
- What makes a password strong: length beats complexityWhy a long password beats a short one full of symbols, how guessing attacks really work, and a simple rule for passwords worth using in 2026.
- Passphrases: four random words and why they beat symbolsHow a passphrase gets its strength, why the words must be chosen randomly rather than by you, and how to build one you can actually remember for the few passwords you must type.
- Why reusing one password is the most expensive habit onlineCredential stuffing explained: how one leaked password becomes a dozen compromised accounts, why attackers do not need to crack anything, and how to unwind reuse in an evening.
- Password managers explained: why one app holding everything is saferHow a password manager works, why putting every password in one place is safer rather than riskier, what happens if the company is breached, and how to start without a weekend project.
- Passwords saved in your browser: good enough or a bad idea?How Chrome, Safari, Edge and Firefox store your logins, when that is fine, when it is risky, and how to check what your browser is holding right now.
- How to check whether your password has already leakedHow breach checking services work without seeing your password, what a match actually means, and the exact order to change things when one of yours turns up.
- Sharing a password without putting it in a messageWhy passwords in chat and email keep leaking, the safe ways to share access at home and at work, and what to use when the other person will not install anything.