Home โ€บ Security โ€บ Create strong passwords

Person creating a strong password on their phone

How to create strong passwords and remember them without writing them down

Updated in 2026 ยท 5 min read

Almost all of us know that "123456" isn't a good password, but many of the ones we use every day aren't much better either. The good news is that creating truly strong passwords doesn't mean memorizing impossible gibberish: with a few simple ideas you can protect your accounts without going crazy trying to remember passwords. We explain how to do it and how to avoid having to memorize them all.

Before you start: if you suspect any of your current passwords has been used on more than one site or may have leaked at some point, change it right now, especially if you use it for your email or online banking.

In this article:

  1. What actually makes a password truly secure
  2. Don't reuse the same password across several important accounts
  3. Use a password manager so you don't have to memorize them all
  4. Two-step verification, an extra layer even if the password leaks

1. What actually makes a password truly secure

For years we've been told that a strong password should mix uppercase, lowercase, numbers and odd symbols. The problem is that this kind of password is so hard to remember that we end up writing it down on paper, in a note on our phone, or reusing the same one every time, which completely defeats its purpose.

What really makes a password strong is, above all, its length. A long phrase that means something to you but isn't obvious to anyone else โ€” for example, joining several unrelated words together โ€” is much harder to guess or for a program to crack than a short word with a couple of symbols tacked onto the end. And on top of that, you'll find it much easier to remember because you can build a mental image out of it.

2. Don't reuse the same password across several important accounts

It's very convenient to always use the same password, but it's one of the most dangerous mistakes. If that password leaks in a data breach at any service that uses it โ€” and breaches happen constantly, even at large companies โ€” anyone can try it on your email, your social media or your online banking.

Using a different password for each important account limits the damage: if one gets stolen, it doesn't compromise all the others. They don't need to be completely different from each other in every character; it's enough that it's not literally the same key opening several doors at once.

3. Use a password manager so you don't have to memorize them all

If every account needs a different, long password, memorizing all of them by heart is practically impossible. This is where a password manager comes in: a tool that stores all your passwords in encrypted form and fills them in automatically when you need them, so you don't have to type or remember them one by one.

There's no need to look for anything complicated or paid: most browsers and operating systems already include a free built-in password manager, ready to use without installing anything extra. The only thing you really need to memorize is a single master password, long and strong, that gives you access to the rest. Take good care of it, because it's the key that opens all the others.

4. Two-step verification, an extra layer even if the password leaks

Not even the longest, most original password in the world protects you completely, because the risk of a service suffering a breach doesn't depend on you. That's why it's worth adding an extra layer of protection: two-step verification.

With two-step verification turned on, even if someone gets your password they'll also need a second element to get in, such as a code that arrives on your phone or that an app generates. It's the difference between a stolen password being a simple scare or turning into a real headache. If you don't have it turned on yet for your most important accounts, it's one of the highest-impact steps you can take today.

โœ” With long, different passwords for each account, a manager that stores them for you, and two-step verification turned on, your accounts stay protected even if a password does end up leaking.
Advertising space (Google AdSense)

Frequently asked questions

Is it better to use a long phrase than a short password with odd symbols?

Yes. A long phrase that only you can remember, even if it uses ordinary words, is usually more secure than a short word full of symbols, because what most makes it hard for someone to guess it or for a program to crack it is length, not the complexity of the characters.

Why shouldn't I use the same password on several accounts?

Because if that password leaks in a data breach at any of those services, whoever gets it will be able to try it on your other important accounts, like email or online banking. Using different passwords means a theft affects only one account, not all of them.

Is it safe to store all my passwords in a password manager?

Yes, it's much safer than reusing passwords or writing them down on paper or an unprotected note. Password managers encrypt all the information and only you can access it with your master password, which is the only one you need to remember by heart.

You might also like

Have questions about this article?

Write them in the comments and we'll help you out. To comment you need to register (with email, Google or Facebook). Comments only load if you accept cookies.