Stop Using password123
September 29, 2026 · 6 min read
Every year, some security company publishes a list of the most common passwords, and every year 123456 and password are still on it. We all know better. We do it anyway, because remembering forty unique passwords is a job nobody applied for. The good news: the actual rules for good passwords got simpler in recent years, not harder. And the best password is one you never have to remember at all.
Length beats cleverness, every time
Here's the math that matters. A password's strength is measured in entropy — roughly, how many guesses an attacker needs. Each character you add multiplies the possibilities. Going from 8 to 12 characters doesn't make your password 50% stronger; it makes it thousands of times stronger.
Compare: Tr0ub4dor! — the classic "clever" password with substitutions — has about 28 bits of entropy. It looks secure. It isn't; password crackers try exactly these substitutions first. Meanwhile correct horse battery staple — four random ordinary words — has around 44 bits. It's easier to type and enormously harder to crack. Length wins. The famous xkcd comic about this is fifteen years old and still right.
Practical rule: aim for at least 16 characters for anything important. For random strings, 20+ is better. The old advice about forced symbols and numbers in every password? NIST — the US standards body — officially walked that back. Complexity requirements mostly just annoy humans while barely slowing attackers.
The real enemy isn't guessing — it's reuse
Here's the uncomfortable truth: most accounts aren't hacked by someone guessing your password. They're hacked because some forum you joined in 2014 got breached, your email + password combo leaked, and attackers tried it on every major site automatically. This is called credential stuffing, and it's fully automated. Your clever password doesn't matter if you used it in two places and one of them leaked.
Which means the #1 rule isn't "make passwords complex." It's "never reuse a password." A unique mediocre password beats a reused great one.
So how do you manage 100 unique passwords?
You don't. A password manager does. Bitwarden (free, open source), 1Password, Apple's Keychain — pick one, let it generate 24-character random strings for every site, and memorize exactly one strong master password. This is the single highest-leverage security habit there is. Everything else is details.
"But what if the password manager gets hacked?" People ask this a lot. Reputable managers encrypt your vault locally; the company never sees your passwords. It's not zero risk — nothing is — but it's orders of magnitude safer than the spreadsheet, the sticky note, or the three passwords you rotate through everything.
Generating good passwords
When you need a password right now — a Wi-Fi key, a database credential, a throwaway account — a generator is the way. What matters in a generator:
- Real randomness. It should use your operating system's cryptographic random number generator (
crypto.getRandomValuesin the browser), notMath.random(), which is predictable. This is non-negotiable. - Length control. 16 for casual, 24+ for important, 32+ for things like API secrets.
- Character sets you can toggle. Some ancient systems choke on symbols; most don't. Include everything unless you have a reason not to.
- It runs locally. A password generator that sends your password to a server defeats the purpose. Ours runs entirely in your browser — and you should demand that of any generator you use.
The short checklist
Use a password manager. Give every site a unique password. Make important ones long (16+ characters). Turn on two-factor authentication wherever it's offered — it's the safety net for when passwords fail. And stop trying to memorize them all; that's the manager's job now.