Skip to content

How to create a strong password that's still usable

P
PassTransfer
Published November 9, 20253 min read

The tension between strength and usability

Security advice about passwords often feels like it was written to make life harder. "Use at least 16 characters, mix upper and lowercase, add numbers and symbols, never use a word found in a dictionary, and make each one unique." All of that is technically correct. None of it explains how a normal person is supposed to remember dozens of such strings.

The good news is that the field has moved on. Modern guidance from organisations like NIST (the US National Institute of Standards and Technology) acknowledges that complexity requirements often backfire — users end up writing passwords on sticky notes or making trivially predictable substitutions like "P@ssw0rd".

What actually makes a password strong

Password strength comes down to one thing: how long it would take an attacker to guess it. That depends on:

  • Length — the single most important factor. Every extra character multiplies the search space exponentially.
  • Unpredictability — no patterns an attacker could exploit (keyboard walks like "qwerty", dictionary words, personal information)
  • Uniqueness — reused passwords mean a breach of one service exposes all others

A random string of 16 characters is far stronger than a clever but short substitution. A passphrase of four to five unrelated random words is both long and memorable.

Practical methods that work

The random passphrase method Choose four or five genuinely random words — not a phrase that means something to you, but words picked at random. "correct-horse-battery-staple" is the famous example. This approach gives you excellent length, reasonable entropy, and something a human can actually type and remember.

The password manager method Let a password manager generate a fully random string — 20 characters, all character types — and store it for you. You never need to type or remember it. This is the strongest option for most accounts and should be the default for anything you access from a device.

The memorable formula for high-stakes accounts For the handful of passwords you genuinely need to remember — your primary email, your device login, your password manager master password — build something long and personal but not guessable. A line from an obscure book, modified with numbers and symbols in a way only you would choose.

What to avoid

  • Predictable patterns: Password1!, Summer2025, CompanyName123
  • Personal information: birthdays, pet names, addresses
  • Short passwords: anything under 12 characters is increasingly vulnerable
  • Reuse: using the same password across multiple services

When you have to share a password

Even a perfectly strong password becomes a liability if it's shared carelessly. When you need to hand a credential to a colleague, client, or contractor, the strength of the password matters less than how securely it travels. A 30-character random string sent in a plain email is more vulnerable than a simple password sent via an encrypted one-time link.

For those moments, use PassTransfer. The password is encrypted, delivered once, and then gone — so the transfer itself doesn't undo all the work you put into creating a strong credential.

The bottom line

Strong passwords are long, random, and unique. Use a password manager for almost everything. Reserve memorised passphrases for the small number of credentials you genuinely need in your head. And when you have to share a password, do it in a way that matches the care you took creating it.

Try PassTransfer for free →

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password