A weak password is like a screen door on a bank vault. It looks like protection, but it will not stop anyone determined to get in. The good news is that a truly strong password does not have to be a jumble of symbols you can never remember.

This guide walks you through a simple method for building passwords that are both hard to crack and easy to recall: the passphrase. You will also learn why “Password123” and similar favorites fail instantly, why reusing one password everywhere is risky, and how a password manager can take the memory work off your plate entirely.

None of this requires special technical skill. It takes about 10 to 15 minutes to update your most important accounts once you know the method.

How do I create a strong password I can actually remember?

Pick three or four random, unrelated words, string them together, and add a number or symbol somewhere in the middle. That combination, called a passphrase, is both longer and easier to remember than a short password full of symbols.

For example, “purple7lantern.garden” is a passphrase. It combines four unrelated ideas (purple, lantern, garden, and the number 7) into one long string. It has no obvious pattern, and it does not describe anything true about your life, so a stranger cannot guess it from your Facebook page.

Plain talk: passphrase

A passphrase is a password made of several ordinary words strung together instead of one word dressed up with symbols. It is longer than a typical password, which makes it much harder for a computer to guess, but it is easier for a person to remember.

Compare that to something like “P@ssw0rd1”, which looks complicated but is one of the very first guesses a password cracking program tries. Swapping letters for symbols (a for @, o for 0) is a trick that criminals’ software already expects.

Why “Password123” and similar passwords fail instantly

Every year, security companies collect lists of the passwords found in real data breaches and rank the most common ones. According to a report on NordPass research covered by Help Net Security, “password,” “123456,” “123456789,” “guest,” and “qwerty” were among the most common passwords found worldwide in 2022. “Password123” and its many variations show up on these lists too.

Here is why that matters: password cracking tools do not have to guess randomly. They start with lists of millions of real passwords pulled from past breaches, plus common patterns like a word followed by a number. A password on that list, or close to it, can be broken in seconds, no matter how clever you thought the capital letter or exclamation point made it look.

Weak habit Why it fails Stronger alternative
One dictionary word plus a number (“Sunshine1”) On every common password list; guessed in seconds Three or four unrelated words strung together
Swapping letters for symbols (“P@ssw0rd”) Cracking tools already expect this trick Length matters more than symbol tricks
Same password on every site One breach exposes every account that shares it A unique passphrase for each important account
Personal details (pet name, birth year) Easy to find on social media Random words with no connection to you

Length matters more than complexity

For years, many websites required a mix of capital letters, numbers, and symbols, assuming that made passwords stronger. Guidance has shifted. The National Institute of Standards and Technology (NIST), the US government’s technology standards body, publishes official guidelines for passwords in its Digital Identity Guidelines, Special Publication 800-63B. NIST recommends favoring length over forced complexity rules, and it no longer recommends making people change a good password on a fixed schedule, only when there is a reason to think it was exposed.

The UK’s National Cyber Security Centre reaches a similar conclusion in its guidance on using three random words: complex rules push people toward workarounds, like writing an easy password on a sticky note, which can be less secure than a long, memorable passphrase.

In practice, that means a longer passphrase like “orange42bicycle.harbor” is stronger than a short, symbol heavy password like “Or4ng3!”, even though the second one looks more complicated at a glance.

Try this

To build a passphrase, think of four things that have nothing to do with each other: an object in the room, a color, a place you have visited, and a small number. String them together with no spaces, using a period or a number as a connector. Write it down once to practice, then type it from memory a few times until it sticks.

Never reuse the same password twice

This is the single biggest password mistake, and it has nothing to do with how strong the password looks. According to research from Google and the Harris Poll reported by Forbes, 65 percent of people admitted to reusing the same password across multiple accounts.

Here is the problem with that habit. When one company gets hacked, which happens to well known companies regularly, the stolen passwords often end up for sale or posted online. Criminals then try those same email and password combinations on banking sites, email accounts, and shopping sites, a technique called credential stuffing. If you used that same password everywhere, one breach you had nothing to do with can hand a criminal access to your bank account.

Safety tip

Give your email account and your banking accounts each their own unique passphrase, never shared with any other site. Your email is especially important to protect on its own, since it is usually the account criminals use to reset all your other passwords.

You can check whether a password you already use has shown up in a known data breach using a free tool called Have I Been Pwned. It compares a scrambled version of your password against a huge list of passwords exposed in real breaches, without ever sending your actual password anywhere. If a password you use comes back as exposed, change it right away, along with any other account where you used something similar.

Should you use a password manager?

Remembering a different, strong passphrase for every account you own is hard work, and that is exactly the problem a password manager solves.

Plain talk: password manager

A password manager is a program or app that stores all your passwords in one encrypted, locked vault. You only need to remember one strong master password to open it. It can also generate a new random passphrase for you every time you sign up for a new account.

The FTC has recommended password managers for people who find it hard to create and remember many strong passwords on their own. When choosing one, look for an established, well reviewed option, and take your time to make the master password itself a strong passphrase, since it protects everything else.

If a stranger ever calls or emails asking you to read out a password, a security code, or your master password, that is a scam, full stop. No legitimate bank, tech company, or government agency will ever ask you for your password over the phone.

Say this

“I don’t give out passwords or codes over the phone. If this is really my bank, I’ll call the number on the back of my card myself.”

Putting it into practice

Follow these steps to strengthen your most important accounts this week:

  1. Make a short list of your most important accounts: email, online banking, and any account with a saved credit card.
  2. For each one, build a passphrase using three or four unrelated words plus a number, following the method above.
  3. Make sure the passphrase on your email account is different from every other account.
  4. If you want help remembering them all, set up a reputable password manager and let it generate and store new passphrases for you.
  5. If you clicked a suspicious link recently or suspect an account was exposed, change that password today rather than waiting.

Building strong passwords works hand in hand with spotting scams before they reach your passwords in the first place. If you think you may have already clicked something you shouldn’t have, our guide on what to do after clicking a scam link walks through a calm, 10 minute checklist. If a scammer already has your bank details, see our guide to the “safe account” scam and how to respond, and our article on freezing your credit after a scam explains a further step worth taking. You can also find local reporting contacts in our guide on where to report a scam.

Where to go from here

Strong, unique passwords are one of the simplest habits that make you a harder target for scammers, and they pair well with knowing the common tricks scammers use in the first place. Our book, Scam Proof, walks through the most common scams older adults face today and how to shut them down calmly, one habit at a time.