Most break-ins do not involve a genius hacker. They happen because a password was weak, or reused on many sites. Here is how to make passwords that are both strong and easy to remember.

Length beats complexity. Forget “P@ssw0rd!” with tricky symbols you will never recall. A long passphrase of a few random words is stronger and easier: something like purple-canoe-lantern-42. The longer it is, the harder it is to crack, and the easier it is for you to remember.

The one rule that matters most: never reuse a password. If you use the same password everywhere and one site gets breached, criminals try that password on your email and bank. Big data breaches happen constantly, so assume any single password could leak someday. A unique password per account means one leak stays contained.

Let a password manager do the remembering. A password manager is a secure app that creates and stores a different strong password for every account. You remember only one strong master passphrase, it remembers the rest and fills them in for you. Your phone or browser already has one built in (Apple, Google, and Microsoft all offer this free), and there are trusted standalone apps too. This is the single biggest upgrade most people can make.

A quick example. You reused one password on a shopping site, a game, and your email. The shopping site is breached. Within days, criminals log into your email with the same password. Had each been unique, the breach would have stopped at the shopping site.

What to do:

  1. Make your email password a long passphrase of 3-4 random words, used nowhere else.
  2. Turn on the password manager built into your phone or browser, or install a trusted one.
  3. Over time, let it replace your reused passwords with unique ones, starting with email and bank.