BuildUtilities

Password Security Best Practices

What Makes a Strong Password?

Password strength is measured by entropy, the number of possible combinations. A strong password should be long (16+ characters), include mixed character types, and be unique for every account.

Entropy & Crack Time

Password TypeExample LengthEntropyCrack Time*
Lowercase only8 chars~38 bitsSeconds
Mixed case + digits12 chars~71 bitsMonths
All character types16 chars~105 bitsCenturies
Random passphrase4 words~55 bitsYears

*Assuming 10 billion guesses per second

Best Practices

  • Use a password manager: Generate and store unique passwords for every service
  • Enable 2FA/MFA: Even strong passwords can be phished
  • Never reuse passwords: A breach on one site compromises all accounts with the same password
  • Avoid personal information: Names, birthdays, and pet names are easily guessable
  • Consider passphrases: "correct-horse-battery-staple" is stronger and easier to remember than "Tr0ub4dor&3"

Hashing for Developers

Never store passwords in plain text. Use a modern hashing algorithm designed for passwords:

bcrypt

Industry standard. Built-in salt and configurable cost factor.

Argon2

Winner of the Password Hashing Competition. Memory-hard to resist GPU attacks.

scrypt

Memory-hard. Good alternative when Argon2 is unavailable.

⚠️ Do NOT use MD5, SHA-1, or SHA-256 for password hashing, they are too fast and vulnerable to brute-force.

Generate strong passwords with our Password Generator and explore hash outputs with the Hash Generator.

FAQ

How often should I change passwords?

NIST recommends changing passwords only when there's evidence of compromise, not on a fixed schedule. Forced rotations lead to weaker passwords.

Are password managers safe?

Yes. A password manager with a strong master password is far safer than reusing passwords or writing them down.

Try These Tools

Related Documentation

Tip Jar