What Makes a Strong Password

What makes a strong password?

Passwords have a branding problem. We’ve spent decades teaching people that a “strong password” looks like this:
P@ssw0rd!2024#

A chaotic soup of symbols, numbers, and mild frustration. It feels secure. What’s more, it looks secure. It’s also, in many cases, not nearly as strong as we think. Because most of what we’ve been told about passwords is outdated, misunderstood, or just plain wrong.

So let’s fix that.

What Actually Makes a Password Strong?

A strong password isn’t about how complicated it looks. It’s about how hard it is to guess.

And that comes down to four things: length, unpredictability, uniqueness, and resistance to real-world attacks.

It has nothing to do with vibes, symbols, or how clever you feel typing it.

1. Length

If there’s one idea modern cybersecurity agrees on, it’s this: length beats complexity.

According to National Institute of Standards and Technology (NIST), password length is the single most important factor in determining strength.

Why? Math.

Every extra character increases the number of possible combinations exponentially. A short “complex” password can be cracked far faster than a long, simple one.

For example:

  • 8-character “complex” password → relatively weak
  • 16-character passphrase → dramatically stronger

In fact, a longer password made of simple words can outperform a short one packed with symbols.

That’s why modern guidance recommends:

  • Minimum: 8 characters
  • Recommended: 12–16+ characters (or more)

If your password feels like a sentence rather than a code, you’re on the right track.

2. Complexity

Here’s where things get counterintuitive. Those classic rules, “add a number, a symbol, an uppercase letter”, don’t work nearly as well as we thought. Why? because humans are predictable.

When forced to be “complex,” we don’t become random. We become patterned:

  • Capital letter at the start
  • Number at the end
  • Exclamation mark for flair

Attackers know this. Their tools are trained on it.  So while mixing character types can help, it’s not the core of strength. In fact, overly complex passwords often backfire because people reuse them, write them down, or slightly tweak them across accounts. All those make them easier to compromise.

3. Unpredictability Is Everything

A strong password should be hard to guess, not just hard to type.

That means avoiding:

  • Dictionary words (“sunshine”)
  • Personal info (names, birthdays, pet names)
  • Common patterns (“qwerty123”, “Password1”)

These are the first things attackers try. Modern cracking tools don’t brute-force blindly. They use massive databases of leaked passwords and human behaviour patterns.

So the real goal is unpredictability. A random-looking password works. However, a weird, unrelated passphrase works even better.

Think:
“velvet suitcase lemon orbit train”

It’s long, strange, and memorable. But most importantly, it doesn’t follow obvious patterns.

The Rise of the Passphrase

If passwords are the old guard, passphrases are the smarter upgrade.

A passphrase is simply a sequence of words strung together. It trades complexity for length and memorability.

Security experts love them because:

  • They’re easier for humans to remember
  • Harder for machines to guess
  • Naturally longer, which boosts security

Instead of fighting your brain with randomness, work with it.

4. Unique Passwords

You can have the strongest password in the world. But if you reuse it, it’s already compromised.

Here’s how most breaches actually play out. First, a small website gets hacked. This leads to your password being leaked. Then, attackers try it on your email, banking, social media And suddenly, everything falls apart.

This is called credential stuffing, and it works because people reuse passwords across accounts. A strong password is not just strong. It’s unique for every single account. No exceptions.

5. Strong Passwords Avoid Known Breaches

Another modern shift: it’s not enough for a password to be “strong.” It also needs to be unused.

NIST recommends checking passwords against databases of previously compromised credentials. Why? Well, because attackers already have lists of millions, sometimes billions, of leaked passwords. If yours is on that list, it doesn’t matter how complex it looks.

It’s already game over.

So, What Does a “Strong Password” Look Like Today?

Let’s rewrite the rules. A strong password is:

  • Long (12–16+ characters minimum)
  • Unpredictable (no obvious patterns or personal info)
  • Unique (never reused across accounts)
  • Not found in breach databases
  • Memorable enough that you won’t sabotage it yourself

And ideally, it’s either:

  • A randomly generated string (best handled by a password manager), or
  • A long, unusual passphrase you can actually remember

Most people think they’re good at passwords. They’re not. That’s not an insult. It’s a design flaw. Humans were never meant to juggle dozens of secure, unique, high-entropy secrets. Which is exactly why password managers exist.

Since it’s that time of the year when we celebrate World Password Day, at pCloud we offer 50% off pCloud Pass Premium, so you can protect your accounts everywhere you log in.

Spread the word: