Skip to content
RU
← All articles

How to Create a Strong Password: Why Inventing One Fails

In short. Strength comes from unpredictability, not from decoration. Substituting characters in a dictionary word adds almost nothing because cracking tools apply the same substitutions, while random length adds a great deal — which is the argument for letting a manager generate it.

"Think of a complicated password" is useless advice, because complicated and random are not the same thing. Asked to produce randomness, a person produces predictability — a property of how minds work rather than a lack of effort. Here is why, what actually makes a password strong arithmetically, and how to get one without relying on imagination.

Why an invented password is nearly always predictable

Ask ten people for a random number from one to ten and seven will say seven. Ask for a password and you get a name, a date, a capitalised word, digits at the end and an exclamation mark. Not because people are lazy, but because a mind reaches for an anchor: anything memorable has to connect to something familiar.

Password crackers are built on exactly this. They do not try every combination in order — they try the likely ones: dictionaries, names, dates, keyboard runs, popular substitutions. A human-invented password lands inside that search space almost every time.

Strength is not how complicated a password looks but how many possibilities it was drawn from. "Looks complicated" and "drawn from a large set" are different properties.
A person picks from a narrow predictable region — exactly the region a cracker checks first.
A person picks from a narrow predictable region — exactly the region a cracker checks first.

What entropy is and why it is the thing measured

Entropy measures the size of the space a password came from. Each bit doubles the count: 40 bits is about a trillion, 80 bits a billion trillion.

The formula is length × log₂(alphabet size). Twelve characters from 94 possibilities give 79 bits. Twenty-four give 157.

PasswordLooksActual bitsGPU cluster
P@ssw0rd!complicated≈10instantly
John1985!solid≈14instantly
Qwerty123456long≈8instantly
zR7#kMx2$Lqvrandom≈79thousands of years
zR7#kMx2$Lqv9!TpW4nGrandom≈131longer than the universe

Look at the first three rows: a dictionary word with substitutions, a name with a year and a keyboard run all contain varied characters, yet their real strength sits between eight and fourteen bits. The cracker knows those patterns and does not try 94 options per position — it tries a dozen rules.

Length sits in the exponent and the alphabet in the base: four letters beat tripling the character set.
Length sits in the exponent and the alphabet in the base: four letters beat tripling the character set.

Length beats the character set

A common belief is that adding symbols strengthens a password. The arithmetic disagrees.

  • Eight lowercase-only characters: 37 bits.
  • Eight characters across all four classes: 52 bits.
  • Twelve lowercase-only characters: 56 bits.

Four added letters beat tripling the alphabet. Length sits in the exponent; the alphabet sits in the base. A short "complicated" password always loses to a long plain one.

Substitutions, a leading capital and a trailing digit add no strength — crackers know those rules.
Substitutions, a leading capital and a trailing digit add no strength — crackers know those rules.

What adds nothing

  • Substitutions a→@, o→0, e→3. Every cracker applies them automatically. P@ssw0rd is the same as password to them.
  • A capital at the start and a digit with an exclamation mark at the end. That is a template, not variety, and it is tried first.
  • Personal data in any form. Names, birthdays, pets, plate numbers — all recoverable from social media and tried early.
  • Keyboard runs. qwerty, 1qaz2wsx and their neighbours are a category of their own in any ruleset.
A cryptographic source fills the whole space evenly; a human fills one corner of it.
A cryptographic source fills the whole space evenly; a human fills one corner of it.

How to get a genuinely random password

  1. For websites, a random string. Sixteen characters is enough for ordinary services, twenty-four for email, banking and anything restoring access to the rest. You do not need to remember it — the manager does.
  2. For what must be remembered, a passphrase. Five random words from a 7776-word list give 65 bits, six give 78. Far easier to hold in mind, comparable in strength.
  3. Check the result. Not by the word "strong" on a meter, but by the bit count and the guessing time.

Both are produced by the password generator. It draws from the Web Crypto API rather than a language's pseudo-random function, shows entropy and guessing time across four attacker models, and checks against breach databases — all in the browser, with nothing sent to a server.

How many characters to use

What it protectsLengthRoughly
Forum, subscription1279 bits
Social network, shop16105 bits
Email, banking, government24157 bits
Manager master password6-word phrase78 bits

The upper limit is set by compatibility rather than security: some sites still truncate passwords at 20 or 32 characters, occasionally without saying so. If login stopped working after a password change, that is the likely cause.

Frequently asked questions

Can a person invent a good password?

In theory yes; in practice almost nobody can, because it requires choosing characters with genuinely equal probability, which minds do not do. Using a generator is easier than fighting your own cognition.

What if a site demands a symbol and my password is words?

Put a separator between the words — a hyphen or a full stop. It satisfies the form and barely changes strength, which comes from the number of words and the size of the list rather than from punctuation.

How important is changing passwords regularly?

Much less than commonly believed. NIST removed the rotation requirement in 2017 because it makes passwords more predictable. Covered in the article on how often to change a password.

Is a word-based password too short in characters?

Character count is irrelevant here. A phrase is measured by word count and list size: five words from 7776 is 7776⁵ possibilities, or 65 bits, however many letters they contain.

In short

  • Looking complicated and being strong are different; what counts is the number of possibilities.
  • A human-invented password nearly always lands where the cracker looks first.
  • Length beats the character set: it sits in the exponent, the alphabet in the base.
  • Substitutions, a leading capital and a trailing digit add nothing.
  • One reliable route: a random string from a generator for sites, a passphrase for what must be remembered.

Check your website right now

Check your site's security →
More articles: Security
Security
How to Check a Website for Malware: 4 Layers and a Cleanup
01.04.2026 · 1 217 views
Security
Cookie Security Flags: HttpOnly, Secure, SameSite
14.03.2026 · 621 views
Security
Web Server Security Hardening Checklist: Nginx and Apache
16.03.2026 · 616 views
Security
How to Check a Website for Fraud: 12 Signs of a Phishing Site
18.07.2026 · 524 views