Blog
Best Practices for Creating a Strong and Secure Password
Tips & Tutorials

Best Practices for Creating a Strong and Secure Password

January 12, 2015, 9 Mins Read.
0%

Today, where nearly each and every aspect of our lives is connected online, having strong passwords is of utmost importance. Also, with data breaches and identity theft cases on the rise, it has become mandatory to pay more attention to effective password security.

Whether you’re managing a personal website or working in web development, strong password practices are essential for protecting user accounts, applications, and sensitive data.

Imagine your passwords as the key to your digital kingdom- protecting everything from your bank account to your social media profiles. Here, having a simple, weak password can end up leaving your front door open for intruders.

So, if you are in search of upgrading your passwords or you are starting from scratch, take control of your online security with the following tips.

What is a strong password?

A strong password is a combination of multiple characters that includes uppercase and lowercase letters, numbers, and special symbols. Instead of common words, phrases, or personal information that are easy to guess, they are usually unpredictable.

Characteristics of strong passwords

  • Are at least eight alphanumeric characters long
  • Contain at least three of the following four categories
  • Uppercase characters (e.g., A-Z)
  • Lowercase characters (e.g., a-z)
  • Digits (e.g., 0-9)
  • Special characters ( e.g., !@#$%^&*()+|~-=\`{}[]:”;’?,./) (Note: Oracle allows only the special character underscore () in a password unless the password is enclosed in quotes.)
  • They are kept private. Passwords should be memorised or, if written down, kept in a locked file cabinet or other secure location.
  • Do not contain a common proper name, login ID, email address, initials, first, middle or last name

Examples of strong passwords

9QxP&29eK!

mC5%v@reL/7#

Zr8T@6Np4Wp

Characteristics of weak passwords

  • The password contains less than eight characters
  • The password is a word found in a dictionary (English or foreign) or a word in any language, slang, dialect, jargon, etc.
  • The password is the same as your username or login name
  • The password is a common usage word such as names of family, pets, friends, computer terms, birthdays or other personal information, or number patterns like aaabbb, dddddd, qwerty, zyxwvuts, 123321, etc.
  • Any of the above spelt backwards
  • Any of the above preceded or followed by a digit (e.g., secret1, 1secret)

Examples of weak passwords

123456 (number pattern)

Sophia000 (name + digit)

tyuio (common keyboard pattern)

Password vs passphrase: which one is better?

A passphrase is eventually a more secure form of a password that is typically longer than a password and contains spaces. Though passwords are shorter, they are hard to remember. In comparison, passphrases are way longer and generally easier to remember.

Also, passphrases are less predictable. For example, you can use random words with numbers or special characters, such as elephant3monkey7!, or you can incorporate a relevant phrase with numbers or characters, such as Rainy#Season6IsHere.

Here are some strong examples of strong passphrases

  • StarryNight$Rides4Moon
  • OceanBreeze#2WarmWaves
  • LightsWill#guide77you9Home

For businesses maintaining websites or customer platforms through professional web development, enforcing strong password policies is a fundamental part of overall cybersecurity.

5 Password security best practices you should follow

Password security best practices

1. Enable multifactor authentication

Multifactor authentication adds an extra layer of security as it adds two of more forms of verification before granting access to an account. The multiple forms of verification typically include something you know such as password or pin number, something you have such as smartphone token and something you are like fingerprints. This is particularly important for administrator accounts that manage websites, applications, or online services built through modern web development.

2. Use a password manager

Password managers store all your passwords in an encrypted format. It transforms the passwords into an unreadable format by using an encryption algorithm. As a result, the owner can only decrypt them only by using the master password. So, all you need to remember is the master password.

In addition, password managers come with advanced security measures like encryption and zero-knowledge architecture that keep your passwords protected even if the database is compromised. Using a password manager’s password generator, you can ensure that each of your passwords is unique and robust.

Some other benefits include cross-device syncing, password sharing, password audit, auto-filling and more.

3. Change the password regularly

Changing passwords on a regular basis is a proactive measure that protects your accounts from any sort of unauthorised access. It works great if you set a schedule in every 3-6 months based on the sensitivity of the information and how frequently your passwords are used.

Whenever you notice any unusual activity like unauthorised logins or changes to account settings, change your passwords immediately. Don’t overlook the security alerts. If a service you use reports a data breach, change your password. Always avoid reusing old passwords; otherwise, it can defeat the purpose of changing them.

4. Monitor account activity

Try to regularly review your activity log, which shows details like the date, time, IP address, and device used to see when and where your account was accessed. Enable notifications for logins from new locations and devices to get real-time awareness of potential security issues.

Organisations should also monitor login activity across every web portal that employees or customers use to quickly identify suspicious access attempts.

You can even use third-party tools or security apps to monitor any suspicious activity. To stay informed, keep an eye on security news related to the services you use.

5. Educate yourself on phishing scams

It is wiser to educate yourself in phishing scams as it is one of the most common methods that cybercriminals use to access to your passwords. And failing victim to a phishing scam can lead to severe consequences. Most of the phishing scams appear very legitimate.

For example, phishing attempt often involve messages that seems urgent or official and ask you to provide sensitive information including passwords.

A list of don’ts

  • Don’t reveal a password over the phone or in person to anyone. Not your boss. Not your family. Not your co-workers. If someone demands a password, refer them to this document.
  • Don’t reveal a password in an email message.
  • Don’t talk about a password in front of others.
  • Don’t hint at the format of a password (e.g., my family name).
  • Don’t reveal a password on questionnaires or security forms.
  • Avoid writing passwords down, but if you must, store them in a secure place (e.g., a locked file cabinet).
  • Passwords should never be stored unencrypted online.
  • Do not use the Remember Password feature of applications (e.g., Eudora, Outlook, Netscape Messenger).
  • Don’t use the default password, if one is provided. Change it immediately to a new, stronger password.
  • Don’t reuse old passwords. NetID passwords cannot be reused within a 12-month period, and passwords cannot be changed to any of the previous three passwords.

Our personal favourites

Take your favourite line from a movie, song, or book and convert it to a passphrase. If you like the scene from A Few Good Men when Jack Nicholson is on the stand, take the line “You want the truth? You can’t handle the truth!” and convert it to Ywtt?Ychtt!.

It has uppercase and lowercase letters, as well as special characters. It is not a word appearing in any dictionary, yet it is simple for you to remember.

Or, use a Tool. The main reason that users choose passwords that are easy to crack is that they want to choose passwords that are easy to remember. It is obviously much easier to remember your dog’s name or type characters in the order they appear on the keyboard, like 123456, than it is to recall a5$jgFD118@Kle45@.

Top Password Generators for Creating Strong Passwords

Creating a strong password from scratch isn’t always easy. That’s why cybersecurity experts recommend using a trusted password generator. These tools create random, highly secure passwords that are much harder to crack than passwords based on names, birthdays, or common words. Many password generators are built into password managers, allowing you to securely store and autofill your credentials across websites and devices.

If you’re managing personal accounts, business systems, or working in web development, using a password generator is one of the simplest ways to strengthen your online security.

1. NordPass Password Generator

NordPass provides a free password generator that creates strong passwords with up to 60 characters. You can customise the password length and choose whether to include uppercase letters, lowercase letters, numbers, and special characters. It also allows you to exclude similar-looking characters, making passwords easier to read without reducing security.

Best for:

  • Creating highly secure random passwords
  • Excluding confusing characters
  • Quick password generation for everyday use

2. Bitwarden Password Generator

Bitwarden is a trusted open-source password manager that includes a powerful password generator. It lets users generate both random passwords and secure passphrases while giving complete control over password length and character combinations. Because it’s available on desktop, mobile, and web browsers, it’s a popular choice for individuals and businesses alike.

Best for:

  • Open-source security
  • Random passwords and passphrases
  • Free password generation across multiple devices

3. 1Password Password Generator

The 1Password password generator focuses on creating both complex passwords and memorable passphrases. Users can customise separators, word count, password length, and character types. Combined with the platform’s security monitoring features, it helps users identify weak or reused passwords.

Best for:

  • Secure passphrases
  • Business users
  • Monitoring password strength

4. Dashlane Password Generator

Dashlane offers an intuitive password generator designed for speed and simplicity. With adjustable password length and character settings, users can instantly generate secure credentials suitable for websites, applications, and online accounts.

Best for:

  • Easy-to-use interface
  • Fast password creation
  • Secure credentials for multiple accounts

5. Proton Pass Password Generator

Developed by the team behind Proton Mail, Proton Pass provides privacy-focused password generation for users who value security and confidentiality. It supports both random passwords and multi-word passphrases while giving users flexible customisation options.

Best for:

  • Privacy-conscious users
  • Secure passphrases
  • Cross-platform password protection

How to Choose the Best Password Generator

The best password generator depends on your needs. Consider the following when choosing one:

  • Generates passwords with at least 16 characters
  • Supports uppercase, lowercase, numbers, and symbols
  • Creates random, unpredictable passwords
  • Includes a secure password manager
  • Works across desktop, mobile, and browser devices
  • Offers encrypted password storage and autofill

Final words

Whether you’re protecting your email, banking account, or a business web portal, following these password security practices significantly reduces security risks. By taking simple steps like turning on multifactor authentication, using a password manager, and staying alert to phishing scams, you can lock up your accounts and keep your personal information secure. So, why not take a moment today to strengthen your passwords? It’s a small effort that can make a big difference in protecting your digital world.

Frequently Asked Questions About Password Generators

Are password generators safe?

Yes. Reputable password generators use secure randomisation methods to create passwords that are significantly stronger than passwords created manually. Choosing a trusted provider helps minimise security risks.

Should I use a password manager with a password generator?

Yes. A password manager securely stores your generated passwords, making it unnecessary to memorise dozens of unique credentials while helping protect your online accounts.

How long should a strong password be?

Cybersecurity experts generally recommend using passwords that are at least 16 characters long. Longer passwords with a mix of letters, numbers, and symbols are much more resistant to brute-force attacks.

Can I use the same password for multiple accounts?

No. Every online account should have its own unique password. Reusing passwords increases the risk of multiple accounts being compromised if one login is exposed in a data breach.

You read a lot. We like that

Subscribe