Back to resources

What Makes a Password Strong

When we were younger, most of us were taught to make passwords with capital and lowercase letters, numbers, and special characters. We make passwords like “Summer2024!” because since it follows the rules, it should be safe, right? Well, not really. To understand why, read below to learn about why some passwords are strong and some are weak.

How attackers actually crack passwords

When a hacker tries to crack a password, they almost never type guesses over and over. Hackers use software that tries millions or even billions of combinations per second. Two things determine how fast hackers can crack your password: how long your password is, and how predictable it is.

Patterns are the first thing hackers look for. Common words, names, years, and substitutions like “@” for “a” are all things hackers look for. “P@ssw0rd” looks like it’s hard to crack, but every hacker tries that swap automatically. Putting patterns in your passwords gives your accounts almost no protection.

Length is the real strength

Every character you add to a password makes the number of possible combinations a hacker has to try bigger and bigger. A short password, even a random one, can be cracked quickly to hacker software. A long password is almost impossible to crack by brute force, because the number of combinations is just so big.

This is why a passphrase(a bunch of random words) often beats a couple of symbols. Something like “correct-battery-lawn-thunder” is long, easy to type, and harder to crack. Hackers have a harder time cracking a long, random password like this than a random 8-character password full of symbols that is shorter and, surprisingly, easier for a computer to crack. Length is important for a password if you want it to actually protect.

Random beats clever

The other important part of a secure password is randomness. Any password based on something real about you can be used against you. For example, if you put your pet’s name, your birthday, or maybe your favorite team intoyour password, hackers can find this information and crack your passwords easily. Hackers can look up this information. Social media makes this information easy to find.

A truly strong password has no meaning and no personal connection at all. It’sjust random characters or random words with no connection to your life. That randomness is exactly what makes it hard for hackers to crack and impossible to look up.

Why this is hard to do by hand

Here’s the thing. The strongest passwords are long and random, which makes them basically impossible to remember. If you tried to memorize a unique 20-character random string for every account, you would obviously not be able to memorize it.. So, people go back to making short, memorable, predictable passwords, the exact kind that are easy to crack.

A password manager stops that problem from happening. It generates long, random passwords for you and remembers them, so you never have to. You keep one strong master password in your head, and the password manager handles everything else.

With HatePassword, the vault holding those passwords is encrypted on your device. The strong passwords the password manager creates are stored safely, and only you can unlock them.

A simple checklist

A strong password is:

  • Long, the more characters the better.
  • Random, with no words or personal things about you.
  • Unique, used on only one account.
  • Never based on a simple pattern or common substitution(like swapping a for @).

You should not just put capital letters and special characters into a password you’ll forget easily. A safe password needs to be long and random, and is made by a password manager which does everything fir you. These are the parts of a password that keeps hackers from hacking into your accounts.