What Makes a Password Strong
Not symbols. Not a capital letter at the front and a "1!" at the end. Strength is entropy: how many guesses an attacker needs on average, which depends on how the password was generated rather than how complicated it looks.
``
entropy = length ร logโ(pool size)
`
| Password | Looks | Real entropy |
|---|---|---|
P@ssw0rd! | Complex | ~14 bits โ in every cracking list |
Summer2024! | Complex | ~20 bits โ season + year is the top pattern |
x7Kq2mWvR9pLz4Tn | Random | 95 bits |
| 20 chars, all sets | Random | 130 bits |
Length Beats Complexity
Each extra character multiplies the search space by the pool size. Each extra character
*class* only widens the pool once.
| Change to an 8-char lowercase password | New entropy |
|---|---|
| Baseline (8 lowercase) | 38 bits |
| Add uppercase | 46 bits |
| Add digits and symbols | 52 bits |
| Instead, make it 16 lowercase | 75 bits |
Doubling the length beats adding every character class you have.Crack Times
At 10ยนยฒ guesses per second โ an offline attack on a fast hash with rented GPUs:
| Entropy | Time to exhaust |
|---|---|
| 40 bits | 9 minutes |
| 60 bits | 18 days |
| 80 bits | 38,000 years |
| 100 bits | 40 billion years |
Against a password stored properly with bcrypt or Argon2, divide the guess rate by about a
billion โ which is the entire point of using a slow hash.Rules Worth Following
One password per account. Reuse is what turns one breach into ten.- 20 characters where you can. Anywhere a manager types it for you, length is free.
- Never reuse across work and personal. The blast radius is what matters.
- Turn on 2FA. It is the only control that survives a password leak.
Where Passwords Actually Leak
Cause Share of breaches Mitigation Reuse after another site's breach Largest single cause A unique password per site Phishing Large A password manager (it will not autofill on the wrong domain) Weak or guessable Moderate Length and real randomness Server-side breach Moderate Not yours to control; 2FA limits the damage
Notice that three of the four are unaffected by how complex an individual password is. Reuse
is the dominant risk, and the only fix is a manager.Storing Them, If You Are the Server
`javascript
// Argon2id is the current recommendation
const hash = await argon2.hash(password, {
type: argon2.argon2id,
memoryCost: 19456, // 19 MiB
timeCost: 2,
parallelism: 1,
});
`
Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per
password and generated by the library. Peppering โ a secret added outside the database โ
helps only if the pepper lives somewhere the database dump does not.
Rules Worth Dropping
NIST SP 800-63B now advises against several long-standing practices:
Forced periodic rotation. It producesPassword1,Password2` and nothing else.- Composition rules. They shrink the search space by making the pattern predictable.
- Password hints and security questions. Both are usually easier to guess than the
- Truncating length. Accept at least 64 characters; a passphrase should fit.