Key Takeaways
  • Make every password at least 16 characters with random mixed characters. Combine uppercase, lowercase, numbers, and symbols — the more random, the harder to crack. The NIST guidelines confirm that length beats complexity every time.
  • Never reuse a password across accounts. The 2026 Verizon Data Breach Report found users are 4x more likely to reuse a compromised password than to choose a weak one. One breach can unlock everything if your passwords overlap.
  • Use a password manager to generate and store passwords automatically. Secrets 4 creates strong, random passwords and autofills them across Mac and iPhone — so you only need to remember one master password.
  • Scan for already-compromised passwords. Strongbox checks your saved passwords against known data breaches and flags anything that's been exposed — a safety net most people skip.
  • Add two-factor authentication to every account that supports it. Step Two keeps all your 2FA codes in one place with iCloud sync and Safari autofill. Even if a password leaks, 2FA stops the attacker.
  • AI makes cracking weak passwords faster than ever — a strong, unique password is your first defense. Try Secrets 4 free for 7 days and let it generate and store bulletproof passwords for every account.

To create a strong password, combine at least 16 random characters — uppercase and lowercase letters, numbers, and symbols — and never reuse it across accounts. That's the baseline. But in 2026, with AI-powered cracking tools and stolen credentials circulating online, the baseline alone won't cut it. 

Google Support shows that things are bad when it comes to creating and maintaining passwords. For example, the most vulnerable passwords are abc123, password, 123456, Qwerty, etc. All of these are extremely easy to guess. 

So if you want to avoid becoming part of the undesirable statistics and trends, here are the seven practices I follow to stay ahead.

How do you create a strong password in 2026?

A good password is one that is easy for you to remember but hard for others to guess. Now, let's look at some of the most important tips to keep in mind when making a password.

Password problemSolution
Passwords too short or simpleUse 16+ random characters mixing letters, numbers, and symbols.
Same password across multiple accountsGenerate a unique password for every account with Secrets 4.
Can't remember dozens of complex passwordsStore them in an encrypted vault with autofill, such as Secrets 4.
Reusing passwords already exposed in data breachesScan your vault for compromised and duplicate passwords with Strongbox.
No two-factor authentication on accountsAdd 2FA codes for all accounts in one app — Step Two.
Passwords stored in plain text or on paperMove to an encrypted, synced password manager, Secrets 4.

When I was setting up my security workflow, I ran my needs through the Productivity Tools GPT assistant to figure out which Mac apps actually covered password management, 2FA, and breach monitoring without overlapping. It saved me from installing five apps when three did the job.

Use a mix of character types

Use a combination of characters, including uppercase letters, lowercase letters, numbers, and symbols. By using a combination of characters, you create a password that is unique and hard to guess. For example, $K80Fx8#8j and i5eBv^h5#.

According to the NIST Digital Identity Guidelines, this randomness exponentially increases the time required to crack your password.

Aim for 16 characters or more

The longer your password, the better. Many sites ask you to create eight-character passwords, but it's better to have at least 16 characters.

The Verizon Data Breach Report found that users are over four times more likely to reuse an already-compromised password than to pick a weak one — and with AI now helping attackers automate credential stuffing at scale, a short or reused password is an open door. Aim for 16 characters or more to stay ahead of brute-force tools that grow faster every year.

Create nonsensical passphrases

Long passwords are good, and even better are long passwords that are made up of random words and phrases. If your letter combinations aren't in the dictionary, your phrases aren't from well-known books, and none of them are grammatically correct, they will be harder to crack.

National Cyber Secutiry Center generally agrees that length is much more important than complexity. 

Give every account its own password

This is the tip most people nod at and then ignore. I was the same until a streaming service breach exposed a password I'd reused on three other sites. Cleaning up that mess took an entire afternoon.

Giving a unique password reduces the risk that a hacker who gains access to one site can use the same password on other sites.

If you ever do get locked out, don't panic; the guide on how to recover a forgotten Mac password covers every recovery method.

Change passwords only when needed

If your information is sensitive, you should change your password more often. Once it has been changed, you shouldn't use that password for a long time. No matter how strong your passwords are, hackers can still try to figure them out.

Use a password manager

Secrets 4 is a secure, encrypted password manager that you can use to store all the sensitive data. A 16-character unique password for every account sounds great in theory, until you have 80 of them.

The app generates strong, random passwords on the spot, stores them in an encrypted vault, and autofills them across your Mac and iPhone so you never have to type or remember a single one. You can store credit cards, secure notes, and software licenses together, synchronize them across devices, and protect them with a single master password.

Autofilling a password with Secrets 4 on Mac

Read also:

What are the most common password mistakes to avoid?

Make sure you know all the don'ts and avoid them when creating your passwords.

Avoid these five common mistakes that weaken even long passwords:

  • Never include your birth year or birth month/day in your password. Also, avoid family names, hobbies, or places of employment. Remember, cybercriminals can easily find this information by snooping on your social media accounts.
  • Don't use names or words from the dictionary. Replace letters with numbers or symbols to make the password harder to guess. Or intentionally use misspellings in the password or passphrase. 
  • Don't reuse passwords. Using the same password to access multiple accounts means hackers can access all of your accounts with a single password. If remembering them all seems like a hassle, consider using a password manager like Secrets 4 or 1Password.
  • Don't use the same password for too long. Changing your passwords regularly dramatically reduces the risk of a hacker discovering and guessing your password.
  • Don't store passwords in an unencrypted text file or document. It would be too easy for cybercriminals to use malware or ransomware to steal a password or a set of passwords and thus gain access to your online accounts. For Mac and iPhone, I recommend using Secrets 4 because it supports Touch ID and Face ID for accessing passwords.

Extra tip: Use 2FA to prevent hijacking your account 

In addition to strong password ideas, you can rely on other security practices to help you protect your data. For example, with two-factor authentication, even if someone steals your password, you can still prevent the intruder from accessing your account. Two-factor authentication adds an extra layer of security to your account by requiring users to provide additional information when they log in.

Additionally, to simplify 2FA, use Step Two to secure access to your accounts. The app collects all your two-step codes in a nice and simple interface. All codes are super easy to copy. 

The annoying part is juggling verification codes across different apps and devices. With Step Two, you scan a QR code once, and the app handles the rest — generating time-based codes for Google, Amazon, X, or whatever else you use. It syncs through iCloud, so your codes follow you across Mac, iPhone, and iPad without setting anything up twice.

How do you manage complex passwords without memorizing them?

Some people prefer to use paper and pen to write down their passwords instead of relying on their memory. Although you can store your passwords in a safe place, such as a locked drawer or safe, it's still not the best option. 

Using a secure, encrypted password manager is a much better way to protect your online accounts. Try Secrets 4 to help you generate and securely store your passwords.

Whenever possible, use two-factor authentication for added security. It requires a second verification step — usually a time-based code — on top of your password. I highly recommend Step Two if you want to make your two-step codes available on all of your Apple devices.

Strong passwords, encrypted storage, and 2FA — your full security stack starts here. Secrets 4, Strongbox, and Step Two are all available on Setapp — 270+ Mac and iOS apps. Cancel anytime. Start My 7-Day Trial.

FAQ

What is an example of a strong password?

A strong password is long, random, and unique. For instance: 2b$Q9tV#1LzK@mP5. Never reuse it on another site. Password managers like Secrets 4 can generate and store these complex passwords for you.

What is a strong 8-character password example?

Eight characters is the minimum many sites allow. An 8-character example is h3%Zk8*Q. If possible, use 12 or more characters for stronger protection. Modern security standards recommend 16+ characters for optimal security.

What are 5 things that make a strong password?

  1. Use at least 16 characters.
  2. Combine upper- and lower-case letters.
  3. Add numbers and symbols.
  4. Avoid personal info and dictionary words.
  5. Create a different password for every account.

A password manager such as Strongbox can generate and remember strong passwords for you.

What is a 12-character strong password example?

Try something like rx9P$7Lb!2Qa. It blends letters, numbers, and symbols, making it tough to crack. Save it in a trusted password manager so you don't have to memorize it.

How often should I change my passwords?

Update a password immediately if it's been leaked or you think someone else knows it. Otherwise, a long, unique password stored in a manager can safely stay in place. Regular changes aren't necessary unless there's a specific security concern.

400+ apps for all your daily tasks.

Sign up to Setapp and try them for free.

Security-tested