A website asks you to make an account, and the rules pop up: eight characters, a capital letter, a number, a symbol. So you type your usual password, add an exclamation mark and move on. This WhatsOnTech guide covers how to create a strong password, but the honest headline comes first: never reusing a password matters far more than how clever it is.
How to create a strong password you can remember
For years the advice was to swap letters for symbols, so “password” became “P@ssw0rd”. Criminals’ guessing software knows those swaps too. What really slows it down is length, because every extra character multiplies the guesses needed.
That is why the UK’s National Cyber Security Centre (NCSC) suggests combining three random words, which makes a password long, unusual and far easier to remember than a jumble of symbols.
- Pick truly random words. Pet names, birthdays and favourite teams are often on your social media, so they are easy guesses.
- Add a symbol only if a site insists. It does no harm, but length does the real work.
The trade-off: this suits the few passwords you must remember, such as your email and password manager, not a hundred accounts. The NCSC says writing those few down is fine if you keep the note somewhere safe.
Why reusing a password is the real danger
Websites get breached (broken into) often, and the stolen email addresses and passwords are traded online. Criminals then use credential stuffing: software tries those leaked pairs on email, shopping and banking logins, like your old key tried in thousands of doors.
So a strong password reused on ten sites is only as safe as the worst-protected of the ten. The WhatsOnTech answer to how to create a strong password starts with a different one for every account, and nobody can remember dozens.
Let a password manager do the remembering
A password manager is an app that creates, stores and fills in your passwords, keeping them in an encrypted vault: scrambled and unreadable without one strong master password or, for built-in managers, your usual device or account sign-in.
- Built-in managers. Apple’s Passwords app (iCloud Keychain), Google Password Manager in Chrome and Android, and those in Microsoft Edge and Firefox. They are free and sync across your signed-in devices.
- Standalone managers. Separate apps for almost any phone, computer and browser, often with paid extras.
The WhatsOnTech view: either kind beats memory. Built-in suits people who stay with one company; standalone suits households mixing brands. Either way, whatever unlocks it must be strong and unique; forget a standalone master password and some managers cannot recover your vault.
A quiet bonus: a manager fills in passwords only on the web address they were saved for. It sometimes misses genuine sites, but if it stays blank on a convincing login page, stop and check, as our guide on how to spot a scam message recommends.
Two-factor authentication and passkeys
Two-factor authentication, also called two-step verification, means logging in needs your password plus something you have, usually your phone, so a stolen password alone is not enough. The options, weakest first:
- A code by text message. Far better than nothing, but criminals can sometimes persuade a mobile network to move your number to their SIM card.
- An authenticator app. A free app shows a new code every 30 seconds or so, not tied to your number. Some services send an “Is this you?” prompt instead; approve it only if you just tried to sign in.
- A security key. A small physical key you plug in or tap. It will not work on a fake site, making it the strongest option.
Security keys and passkeys use standards from the FIDO Alliance, an industry group, and the US Cybersecurity and Infrastructure Security Agency calls FIDO the only widely available phishing-resistant sign-in, meaning a fake website cannot trick it.
Never read out or forward a code; anyone asking is trying to sign in as you. Write down any backup codes a service offers and keep them away from your phone, in case you lose it. Our guide to backing up your files covers what else a lost phone takes with it.
Passkeys: signing in without a password
A passkey replaces the password: you sign in with the fingerprint, face scan or PIN that unlocks your device. There is nothing to guess, reuse or type into a fake site, because a passkey only works on the site it was made for.
Look for passkeys in an account’s security settings; Google and Microsoft accounts offer them, as do many other sites. The WhatsOnTech take: start with your email, but keep your passwords, since plenty of sites still lack passkeys.
Passkeys usually sync through your password manager, so they are only as safe as your devices. Use a screen lock and a phone that still gets security updates, as our smartphone buying guide explains.
Where to start: a short priority list
You need not fix everything at once. WhatsOnTech suggests this order:
- Your email first. Password resets for almost everything go to your inbox, so whoever controls it can take over the rest. Give it a unique password and two-factor sign-in.
- Banking and payments next. Your bank, card apps and any shop or streaming account that stores your card. If you are trimming streaming subscriptions, update passwords as you go.
- Everything else, gradually. Update the rest as you log in, letting your manager create fresh passwords, and close accounts you no longer use.
Check whether your email was in a breach
Free tools such as Have I Been Pwned show which known breaches included your email address, and many password managers flag leaked passwords. A match means your details were in a stolen list, not that your account was broken into. The NCSC’s data breach guidance says to change that password everywhere you used it and watch for scam messages about the breach.
The takeaway
Knowing how to create a strong password helps, but the bigger win is making every password different and letting a manager carry the load. Add two-factor sign-in where it matters, try passkeys where offered, and start with your email. None of it needs technical skill, just a spare hour and a sensible order. That calm, one-step-at-a-time approach runs through every WhatsOnTech cybersecurity guide.