16-Character Passwords
Sixteen characters is the practical default. It clears every corporate policy, is long enough that brute force stops being a consideration at all, and is short enough that the rare system with an undocumented length cap will still accept it.
If you use a password manager — and you should — there is no reason to type it, so the only argument against going longer is compatibility.
The Entropy of This Setting
Drawing 16 characters from an alphabet of 92 — upper case, lower case, digits and punctuation — gives about 104 bits of entropy. At a trillion guesses a second, which is what a well-funded attacker with GPUs achieves against a fast hash, exhausting half that space takes 3.2 × 10^11 years.
| Length | Entropy | Time to crack at 10¹² guesses/sec |
|---|---|---|
| 8 characters | 52 bits | 38 minutes |
| 12 characters | 78 bits | 4,789 years |
| 16 characters | 104 bits | 3.2 × 10^11 years |
| 20 characters | 130 bits | 2.2 × 10^19 years |
| 24 characters | 157 bits | 2.9 × 10^27 years |
| 32 characters | 209 bits | 1.3 × 10^43 years |
Symbols Add Less Than People Think
Moving from 62 characters to 92 adds about 0.6 bits per character. On a 16-character password that is roughly 9 bits — real, but worth less than adding two more letters. Symbols matter mainly because they defeat dictionary and pattern attacks, not because of the arithmetic.
Some systems still reject particular symbols, or silently truncate at a length you cannot see. If a password fails to work after being accepted, that is usually why.
Generated in Your Browser
The generator uses crypto.getRandomValues(), the platform's cryptographically secure
random source, not Math.random() — which is fast, predictable and unfit for this purpose.
Nothing is transmitted and nothing is logged; the value exists only in your tab.
What to Pair It With
At this length brute force stops being the threat, so the remaining improvements are structural:
- A password manager, which makes a unique password per site free rather than a chore.
- Two-factor authentication. An app-based or hardware second factor defeats a stolen
- Passkeys where offered. They remove the shared secret entirely, so a phishing site has
A 16-character password reused across five sites is weaker in practice than five distinct 12-character ones.
Where Passwords Actually Leak
| Cause | Share of breaches | Mitigation |
|---|---|---|
| Reuse after another site's breach | Largest single cause | A unique password per site |
| Phishing | Large | A password manager (it will not autofill on the wrong domain) |
| Weak or guessable | Moderate | Length and real randomness |
| Server-side breach | Moderate | Not yours to control; 2FA limits the damage |
Storing Them, If You Are the Server
``javascript
// Argon2id is the current recommendation
const hash = await argon2.hash(password, {
type: argon2.argon2id,
memoryCost: 19456, // 19 MiB
timeCost: 2,
parallelism: 1,
});
`
Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per
password and generated by the library. Peppering — a secret added outside the database —
helps only if the pepper lives somewhere the database dump does not.
Rules Worth Dropping
NIST SP 800-63B now advises against several long-standing practices:
Forced periodic rotation. It producesPassword1,Password2` and nothing else.- Composition rules. They shrink the search space by making the pattern predictable.
- Password hints and security questions. Both are usually easier to guess than the
- Truncating length. Accept at least 64 characters; a passphrase should fit.