The password rules you were taught — a capital, a number, a symbol, change it every 90 days — are the ones current guidance specifically tells organisations to stop enforcing.
Entropy, and why length wins
Strength is the number of guesses an attacker must make on average. That depends on the size of the character set and the length — and length is an exponent, which is why it dominates.
An eight-character password from the 95 printable ASCII characters has 95^8 possibilities, about 6.6 quadrillion, roughly 52 bits. Four words drawn randomly from a 7,776-word list has 7776^4, about 3.7 quadrillion — comparable. Add a fifth word and it is 2.8 × 10^19, roughly 64 bits, which is thousands of times stronger and still memorable.
| Password | Entropy | Offline cracking time |
|---|---|---|
| password123 | ~10 bits | Instant — it is on every list |
| P@ssw0rd! | ~28 bits | Seconds — a predictable substitution |
| Tr0ub4dor&3 | ~28 bits | Seconds |
| 8 random chars | ~52 bits | Hours to days |
| 4 random words | ~52 bits | Hours to days |
| 5 random words | ~64 bits | Centuries |
| 16 random chars | ~105 bits | Beyond feasible |
Times assume a fast offline attack against a poorly hashed database — millions to billions of guesses a second on consumer hardware. Against a well-implemented site with rate limiting, everything above 40 bits is fine. You cannot know which kind of site you are on, so assume the worst.
Why composition rules make things worse
"At least one uppercase, one number and one symbol" sounds like it adds entropy. In practice it removes it, because humans satisfy the rule in predictable ways.
Told to add a capital, almost everyone capitalises the first letter. Told to add a number, they append 1, or the year. Told to add a symbol, they append ! or substitute @ for a. Cracking tools encode all of these as rules and apply them automatically — so P@ssw0rd! is not meaningfully harder than password.
This is why NIST SP 800-63B stopped recommending composition rules. The current guidance is: allow at least 64 characters, allow all printable characters including spaces, screen new passwords against known-breached lists, and otherwise let people choose.
Expiry rules were counterproductive too
Forced 90-day rotation was near-universal and is now explicitly discouraged, for a reason that is obvious once stated.
People do not generate a fresh random password every quarter. They increment: Summer2025! becomes Autumn2025!. An attacker with one old password can guess the current one immediately. Rotation also pushes people toward simpler passwords, because complex ones are painful to change repeatedly.
The current recommendation is to change a password when there is evidence of compromise, and not otherwise. Both NIST and the UK NCSC now say this.
Reuse is the actual risk
Nearly every account compromise that reaches the news is credential stuffing, not cracking. Attackers take username and password pairs from one breach and try them everywhere else.
Against that, password strength is irrelevant. A 30-character random password reused on two sites is fully compromised the moment either is breached. A weak but unique password is compromised on exactly one.
- Unique per site matters more than strength per site.
- A password manager is the only practical way to achieve that at scale.
- Two-factor authentication stops credential stuffing even when the password is known — an app or hardware key rather than SMS, which is interceptable.
- Check your addresses against breach databases and change anything that appears.
Generating passwords you can actually use
Different accounts want different shapes, and the right answer is not one style everywhere.
- Anything a manager fills — long random characters. You never type it, so length costs nothing. 20+ characters.
- Anything you type regularly — a passphrase. Your device unlock, your manager's master password, a work login. Five random words.
- Anything you read aloud — a passphrase, with no ambiguous characters. Explaining a symbol string over the phone is its own punishment.
- The master password — the longest passphrase you will reliably remember, written down and stored physically somewhere safe. A password on paper in a drawer is a better risk than one you forget.
The Password Generator produces both styles and reports the entropy, which is the number that predicts guessing time. It uses the browser's crypto random source, not Math.random, and runs on your device — a password that travels to a server to be generated is not one you should use.
Frequently asked questions
Is a passphrase really stronger than a complex password?
For the same memorability, yes and by a wide margin. Five random words is around 64 bits of entropy; a typical human-chosen eight-character "complex" password is nearer 28, because people satisfy composition rules in predictable ways that cracking tools already encode.
How long should a password be?
16+ random characters where a manager fills it, since length costs you nothing there. Four to five random words where you have to type it. Below about 12 characters, no amount of character variety compensates.
Should I change my passwords regularly?
No — current NIST and NCSC guidance both say change on evidence of compromise, not on a schedule. Forced rotation makes people increment predictably, so an attacker with the old password can often guess the new one.
Do I still need special characters?
Not as a rule. They add little entropy compared to length, and mandating them pushes people toward predictable substitutions. Use them if the site demands them, but do not treat them as what makes a password strong.
What matters more, strength or uniqueness?
Uniqueness, by a long way. Almost all account compromise is credential stuffing — reusing pairs from one breach elsewhere. A very strong password reused on two sites falls with either one; a weak unique one falls with exactly one.
Is it safe to use an online password generator?
Only if it generates locally. A password produced on someone else's server has been transmitted before you ever used it. Check that the tool runs in your browser and uses the crypto random source rather than Math.random, which is predictable.