Why password strength matters

Most account break-ins come from passwords that are short, reused or already leaked, not from clever hacking. A strong password makes automated guessing impractical, and a unique one stops a breach at one site from unlocking your other accounts.

What makes a password strong

Length and true randomness matter far more than symbols swapped in for letters. Current guidance, such as NIST SP 800-63B, favours long passwords over complicated composition rules.

  • Use at least 14 to 16 characters for important accounts.
  • Let a generator pick the characters. Human-chosen patterns like Summer2026! are easy for attackers to guess.
  • Never reuse a password between sites.
  • Avoid names, birthdays, keyboard runs and common words.

Random password or passphrase?

A random 16-character password drawn from letters, numbers and symbols has roughly 105 bits of entropy. A passphrase of five random words from a 7,776-word list has about 65 bits, and six words about 78 bits. Passphrases are easier to type and remember, so they suit passwords you must enter by hand, such as a password manager master password or a device login. Random passwords suit everything a manager can fill in for you.

How to create one with Serpgy

  1. Open the Password Generator and set the length to 16 or more.
  2. Keep letters, numbers and symbols enabled unless a site rejects certain characters.
  3. Generate, copy and paste it straight into a password manager.
  4. For a memorable option, use the Passphrase Generator and choose five or six words.

Habits that protect you more than any single password

  • Store passwords in a reputable password manager instead of a notebook or browser note.
  • Turn on two-factor authentication, preferably an authenticator app, security key or passkey, for email, banking and social accounts.
  • Change a password immediately if the site reports a breach.
  • Do not share passwords over chat or email.

Common questions

Are generated passwords safe to use? Yes. Serpgy generates them in your browser using secure randomness, and they are not sent to any server. Should I change passwords regularly? Not on a fixed schedule; change them when there is a reason, such as a breach or shared access.