How long should a password be?
Learn why longer random passwords are stronger and how to handle a website’s length limits.
Longer random passwords are usually harder to guess because there are many more possible combinations. Length works best when the password is also random and used for only one account.
Use the longest length the account accepts
If an account allows 8 to 15 characters, aim for 15. If it says “alphanumeric,” use letters and numbers without punctuation. The alphanumeric generator can make one that fits.
Some sites have short limits or reject certain symbols. Those are limits of that site, not signs that a short password is strong. Check the rules before generating a password, and make sure the site does not cut off characters without telling you.
Never use a password shown as an example
River7K2 and Blue!Cloud7? show what different formats look like. They are printed on a public webpage, so they are not safe passwords. Always generate your own.
The 8, 12, 16, 20, 24, 32, and 64-character pages give you starting points for different account rules. Choose the longest option the account accepts. Very short settings are available for old systems with strict limits, not because short passwords are generally safe.
A password manager makes long random passwords much easier to use. If you must type a password by hand, a randomly generated passphrase may be more practical.