Stop Using password123

September 29, 2026 · 6 min read

Every year, some security company publishes a list of the most common passwords, and every year 123456 and password are still on it. We all know better. We do it anyway, because remembering forty unique passwords is a job nobody applied for. The good news: the actual rules for good passwords got simpler in recent years, not harder. And the best password is one you never have to remember at all.

Length beats cleverness, every time

Here's the math that matters. A password's strength is measured in entropy — roughly, how many guesses an attacker needs. Each character you add multiplies the possibilities. Going from 8 to 12 characters doesn't make your password 50% stronger; it makes it thousands of times stronger.

Compare: Tr0ub4dor! — the classic "clever" password with substitutions — has about 28 bits of entropy. It looks secure. It isn't; password crackers try exactly these substitutions first. Meanwhile correct horse battery staple — four random ordinary words — has around 44 bits. It's easier to type and enormously harder to crack. Length wins. The famous xkcd comic about this is fifteen years old and still right.

Practical rule: aim for at least 16 characters for anything important. For random strings, 20+ is better. The old advice about forced symbols and numbers in every password? NIST — the US standards body — officially walked that back. Complexity requirements mostly just annoy humans while barely slowing attackers.

The real enemy isn't guessing — it's reuse

Here's the uncomfortable truth: most accounts aren't hacked by someone guessing your password. They're hacked because some forum you joined in 2014 got breached, your email + password combo leaked, and attackers tried it on every major site automatically. This is called credential stuffing, and it's fully automated. Your clever password doesn't matter if you used it in two places and one of them leaked.

Which means the #1 rule isn't "make passwords complex." It's "never reuse a password." A unique mediocre password beats a reused great one.

So how do you manage 100 unique passwords?

You don't. A password manager does. Bitwarden (free, open source), 1Password, Apple's Keychain — pick one, let it generate 24-character random strings for every site, and memorize exactly one strong master password. This is the single highest-leverage security habit there is. Everything else is details.

"But what if the password manager gets hacked?" People ask this a lot. Reputable managers encrypt your vault locally; the company never sees your passwords. It's not zero risk — nothing is — but it's orders of magnitude safer than the spreadsheet, the sticky note, or the three passwords you rotate through everything.

Generating good passwords

When you need a password right now — a Wi-Fi key, a database credential, a throwaway account — a generator is the way. What matters in a generator:

The short checklist

Use a password manager. Give every site a unique password. Make important ones long (16+ characters). Turn on two-factor authentication wherever it's offered — it's the safety net for when passwords fail. And stop trying to memorize them all; that's the manager's job now.

Try it: our free Password Generator uses cryptographic randomness, lets you set length and character sets, and never sends anything anywhere — the password is generated in your browser and stays there.