Password Security Best Practices
What Makes a Strong Password?
Password strength is measured by entropy, the number of possible combinations. A strong password should be long (16+ characters), include mixed character types, and be unique for every account.
Entropy & Crack Time
| Password Type | Example Length | Entropy | Crack Time* |
|---|---|---|---|
| Lowercase only | 8 chars | ~38 bits | Seconds |
| Mixed case + digits | 12 chars | ~71 bits | Months |
| All character types | 16 chars | ~105 bits | Centuries |
| Random passphrase | 4 words | ~55 bits | Years |
*Assuming 10 billion guesses per second
Best Practices
- Use a password manager: Generate and store unique passwords for every service
- Enable 2FA/MFA: Even strong passwords can be phished
- Never reuse passwords: A breach on one site compromises all accounts with the same password
- Avoid personal information: Names, birthdays, and pet names are easily guessable
- Consider passphrases: "correct-horse-battery-staple" is stronger and easier to remember than "Tr0ub4dor&3"
Hashing for Developers
Never store passwords in plain text. Use a modern hashing algorithm designed for passwords:
bcrypt
Industry standard. Built-in salt and configurable cost factor.
Argon2
Winner of the Password Hashing Competition. Memory-hard to resist GPU attacks.
scrypt
Memory-hard. Good alternative when Argon2 is unavailable.
⚠️ Do NOT use MD5, SHA-1, or SHA-256 for password hashing, they are too fast and vulnerable to brute-force.
Generate strong passwords with our Password Generator and explore hash outputs with the Hash Generator.
FAQ
How often should I change passwords?
NIST recommends changing passwords only when there's evidence of compromise, not on a fixed schedule. Forced rotations lead to weaker passwords.
Are password managers safe?
Yes. A password manager with a strong master password is far safer than reusing passwords or writing them down.