Skip to content
Konvertavimas.lt
Support this project

How to Create a Strong Password You Can Actually Manage

Weak and reused passwords are among the most common reasons accounts get hacked. The good news is that a strong password is easy to create once you know what matters. This guide explains how to make one and how to cope with dozens of accounts.

What makes a password strong

Two factors matter most: length and unpredictability. Each extra character multiplies the number of guesses an attacker needs rather than adding a few, so long passwords beat short but complicated ones.

Unpredictability means the password should not be built from words or patterns attackers try first: names, birthdays, keyboard runs like qwerty, or popular substitutions such as a to @. Cracking software has known these tricks for years.

How many characters are enough

A simple rule: for accounts stored in a password manager that you never need to memorize, use at least 16 random characters. For a master password or a computer login that you must remember, a passphrase of several words is a better fit.

A random 16-character string of upper and lower case letters, digits, and symbols is so complex that brute-forcing it is practically impossible. For this reason length often matters more than how many character types you use.

Passphrases: long but memorable

A passphrase is several randomly chosen words, for example four or five words from unrelated areas. It is long, therefore strong, and easier to remember than something like X7#qL9!z.

What matters is that the words are chosen randomly, not taken from a favorite quote or song. People are bad at picking randomly: once you think of the words yourself they become predictable. It is better to use a generator or roll dice to pick words.

Use a generator

The human brain is a poor source of randomness. A password generator produces a truly random string and lets you choose the length and character set. The Konvertavimas.lt generator runs in your browser: the password is created on your device and never sent anywhere.

  • Choose a length: at least 16 characters for passwords kept in a manager.
  • Leave all character types on, unless a site rejects some symbols.
  • Copy the password straight into your manager or the sign-up form.
  • Do not send it in a message or keep it in a file called passwords.

One password per account

Even a strong password becomes dangerous when it is used in several places. When one site is breached, attackers try the same credentials on other services. That is why every account needs its own password.

This is realistic only with a password manager that remembers everything for you. You memorize one long master passphrase, and the manager creates and fills in the rest.

Common password mistakes

  • A name, birth year, or pet name with a number at the end: these are the first guesses.
  • The same password with a small tweak on different sites, for example adding the site name.
  • Writing passwords on a sticky note by the monitor or keeping them in unprotected browser notes.
  • Sharing a password over chat apps or email, where it stays in the history for years.
  • Recovery question answers that can be found on social media, such as a mother's maiden name. It is better to fill them with random answers and store them in your manager.

Extra protection

  • Turn on two-factor authentication for important accounts: email, banking, cloud storage. An authenticator app is better than SMS.
  • Change a password when a service reports a breach, not every month for no reason.
  • Store recovery codes separately, for example printed and kept in a safe place.
  • Be careful with links in emails: even a strong password will not help if you type it into a fake site yourself.

Frequently asked questions

Try the tools

More guides