Hire me
HOW-TO GUIDE

Password generator guide: create unbreakable passwords

'Password123' protects nothing. This guide shows how to generate truly strong passwords in seconds, store them so you never forget, and lock down the accounts that matter most — explained simply, no jargon.

Published October 9, 20269 min readBy Sharjeel Tahir

What makes a password actually strong?

Length matters more than complexity: a 16-character random password is astronomically harder to crack than an 8-character 'clever' one. Strength comes from length plus unpredictability — random generation beats any human-invented pattern, because attackers' tools are built to guess human patterns first.

Forget everything about substituting @ for a and 0 for o — attackers automated those tricks decades ago. Password strength is math: each additional character multiplies the guesses needed. An 8-character password using all character types has about 6 quadrillion combinations — sounds huge, but modern cracking rigs try billions of guesses per second. A 16-character password has 95¹⁶ combinations — more than all the grains of sand on Earth, squared. Length is the whole game.

The hierarchy of password quality, from worst to best:

  • Terrible: dictionary words, names, birthdays, 'password123' — cracked instantly.
  • Weak: short with substitutions ('P@ssw0rd!') — cracked in hours; these patterns are in every attack dictionary.
  • Okay: long human phrases you invented — better, but humans are predictable.
  • Strong: 16+ characters from a random generator, unique per site — practically uncrackable.
  • Strongest: random 20+ characters stored in a password manager, plus two-factor authentication.

Uniqueness matters as much as strength. When a website is breached (it happens constantly), attackers try your leaked email+password on *every other site* — 'credential stuffing'. One reused password turns a breach at a forum you forgot about into access to your email and bank. Unique passwords per site contain every breach to that one site.

Generate yours with the password generator — 16–20 characters, all character types, generated locally in your browser so the password never touches a server.

How do you generate a strong password step by step?

Open a password generator, set length to 16–20 characters, include uppercase, lowercase, numbers and symbols, generate, and save it immediately in a password manager or written notebook. Generate a fresh unique password for every account — never reuse, never 'tweak' one password across sites.

The 30-second process:

  • Open the password generator. It runs in your browser — generated passwords are never sent anywhere.
  • Set length to 16–20. Longer is stronger; 16 is the practical minimum today, 20+ for email and banking.
  • Include all character types. Uppercase, lowercase, numbers, symbols — maximum unpredictability per character.
  • Generate and copy. One click gives you something like 'k7#mQ2$vL9@nX4!wZ' — ugly, perfect.
  • Save it immediately. Into your password manager (or written down — see below) *before* you paste it into the site. The gap between generating and saving is where passwords get lost.

What about sites with annoying rules ('max 12 characters', 'no symbols')? Generate within their constraints — a 12-character random password still beats any human invention. And if a site emails you your password in plain text or shows it on screen after signup, that's a red flag about *their* security; use a unique password there and consider whether you trust them.

Passphrases are the human-friendly alternative: 5–7 random words ('correct horse battery staple' style) give enormous strength and are typable. They're ideal for the few passwords you must memorize — your password manager's master password and your device PIN. For everything else, random characters stored in the manager win.

How do you remember all these passwords?

Don't — use a password manager (Bitwarden, Apple's Keychain, Google Password Manager) that remembers them for you and fills them in automatically. You memorize exactly one strong master passphrase; the manager handles the other hundred. A written notebook kept at home is a legitimate low-tech fallback.

The average person has 100+ accounts. Memorizing 100 unique 16-character passwords is impossible — which is exactly why people reuse passwords, and why breaches cascade. A password manager solves this structurally: it generates, stores and auto-fills passwords, locked behind one master passphrase only you know.

Good free options: Bitwarden (free, open-source, all devices), Apple iCloud Keychain (built into iPhone/Mac, excellent if you're in that ecosystem), Google Password Manager (built into Chrome/Android, fine for everyday use). All three sync across your devices and warn you about reused or breached passwords. Pick one, install it everywhere, and migrate accounts gradually — email first, then banking, then everything else.

Your master passphrase deserves care: 5+ random words you can type reliably, memorized and never written digitally. This single passphrase protects everything — make it long, make it memorable, and never reuse it anywhere.

No smartphone or distrust software? A paper notebook kept at home is a genuinely reasonable fallback — burglars don't steal password notebooks, hackers can't reach paper. Write site names and passwords, keep it somewhere private, and never photograph it. It's less convenient than a manager but infinitely better than reuse.

What *not* to do: browser 'save password' without a master lock on a shared computer, sticky notes on the monitor, a notes-app file called 'passwords', or the same password with a number incremented per site ('Bank1', 'Bank2' — attackers try exactly this).

What is two-factor authentication and do you need it?

Two-factor authentication (2FA) requires a second proof beyond your password — usually a code from an authenticator app or SMS — so a stolen password alone can't access your account. Yes, you need it: enable it on your email, banking, and social accounts today. It blocks the vast majority of account takeovers even when passwords leak.

Passwords leak constantly — breaches, phishing, shoulder-surfing. 2FA means the leaked password isn't enough: the attacker also needs your phone. It's the single highest-value security upgrade available, taking about two minutes per account.

The 2FA methods, ranked:

  • Authenticator app (best common option): Google Authenticator, Microsoft Authenticator, or Authy generate 6-digit codes that change every 30 seconds. Works offline, immune to SIM-swap attacks.
  • SMS codes (good, not great): better than nothing, but vulnerable to SIM-swap fraud — where an attacker convinces your carrier to move your number to their SIM. Use app-based 2FA for important accounts.
  • Hardware keys (strongest): a physical USB/NFC key like YubiKey. Overkill for most people, ideal for high-risk targets.
  • Email codes (weakest 2FA): if your email is the account being protected, this is circular. Fine as a backup, not as the primary.

Critical: save the backup/recovery codes each service shows when you enable 2FA — screenshot them into your password manager or write them in your notebook. Lose your phone without backup codes and you're locked out of your own accounts, sometimes permanently.

Priority order for enabling 2FA: email first (it's the master key — password resets for everything flow through it), then banking and Easypaisa/JazzCash, then social media and cloud storage, then everything else. An attacker in your email owns your digital life; lock that door first.

How do you check if your passwords were leaked?

Search your email on Have I Been Pwned (haveibeenpwned.com) to see which breaches exposed your data. If an account appears, change that password everywhere it was reused, enable 2FA, and treat any shared security answers as compromised. Check annually — new breaches surface constantly.

Billions of credentials circulate from past breaches — there's a good chance at least one of your old passwords is out there. Checking is free and takes a minute: enter your email at Have I Been Pwned and it lists every known breach involving that address, what data was exposed (passwords? phone numbers?), and when.

If you appear in breaches: don't panic, act. Change the password on the breached service *and everywhere you reused it*. Enable 2FA on those accounts. If security questions were exposed (mother's maiden name etc.), those answers are burned — change them where possible, and note that 'security questions' are just weak backup passwords: answer them with random strings stored in your manager, not true personal facts anyone could look up.

Watch for the breach-notification phish: scammers email 'your account was breached, click here to secure it' — which is itself the attack. Real breach response happens by *you* going to the site directly (type the address yourself), never by clicking the email's link.

Going forward, most password managers and both Chrome and iPhone now warn you automatically when a saved password appears in a new breach. That's yet another reason to keep credentials in a manager rather than your memory — it watches what you can't.

What should you do in the next 10 minutes?

Install a password manager, change your email password to a fresh 20-character generated one, enable 2FA on your email, check Have I Been Pwned, and generate new unique passwords for banking and social accounts. Ten focused minutes on email-first security eliminates the most common ways accounts actually get stolen.

Security advice fails when it's a 40-item list. Here's the minimum effective dose, in order:

  • Minute 0–2: Install Bitwarden (or enable iCloud Keychain / Google Password Manager). Create your master passphrase — 5 random words, memorized.
  • Minute 2–4: Generate a new 20-character password for your email and save it in the manager. Email is the master key to everything.
  • Minute 4–6: Enable 2FA on your email (authenticator app). Save the backup codes in the manager.
  • Minute 6–8: Check your email on Have I Been Pwned. Change passwords on anything breached.
  • Minute 8–10: New unique passwords + 2FA for banking/Easypaisa/JazzCash and your main social account.

After that, migrate remaining accounts opportunistically — each login is a chance to replace a reused password with a generated one. In a month of normal use, you'll have converted the accounts that matter without a dedicated project.

Share this plan with family, especially parents: older relatives are prime targets for phishing and SIM-swap fraud, and 'install a password manager, turn on 2FA for email' is advice simple enough to actually follow. The strongest security system is the one people really use.

Generate a strong password now

16–20 random characters in one click — generated in your browser, never sent anywhere. Free, no sign-up.

Open the password generator ↗

Frequently asked questions

How long should my password be?

16 characters minimum for important accounts, 20+ for email and banking. Every extra character multiplies cracking time enormously — length matters far more than clever substitutions like @ for a.

Is it safe to use an online password generator?

Yes, if it generates passwords locally in your browser (like this site's tool) — the password never leaves your device. Avoid generators on sites you don't trust, and never use a password someone else generated for you.

Are passphrases better than random passwords?

For passwords you must memorize (master passphrase, device PIN), yes — 5+ random words are both strong and typable. For the other 100 accounts stored in a manager, random characters are better since you never type them.

Should I change passwords regularly?

No — forced rotation is outdated advice that produces weaker passwords ('Summer2024!' → 'Winter2024!'). Change a password when there's a reason: a breach, suspected phishing, or you shared it. Otherwise a strong unique password plus 2FA stands.

What if I forget my password manager's master password?

Most managers can't recover it — that's the point of the encryption. Write the master passphrase on paper, store it somewhere safe at home (separate from your devices), and practice typing it until it's muscle memory.

Is writing passwords in a notebook really okay?

As a fallback, yes — it's far better than reusing passwords. Physical theft of a notebook is rare; remote hacking of reused passwords is constant. Keep the notebook at home, never photograph it, and consider it a stepping stone to a password manager.

Portrait of Sharjeel Tahir
About the author

By Sharjeel Tahir

He builds free online tools — including the password generator and QR code generator referenced in this guide — and writes practical how-to articles on everyday digital security.

Published: 2026-10-09