




For years, most of us were taught the same password rules: Use a capital letter, add a number, throw in a symbol, and change your password regularly.
That advice made passwords look complicated, but it did not always make them much harder for criminals to crack.
Today, cybersecurity guidance has changed. One of the most important things to remember about a password is simple: Length matters.
When we picture someone trying to figure out a password, we may imagine a person typing guesses one at a time. In reality, attackers can use automated tools to test huge numbers of combinations very quickly. They can also start with lists of common passwords, words and predictable patterns people often use.
That means a password such as P@ssw0rd1! may look complicated to us, but it is not especially difficult for a computer to recognize. Attackers already know people commonly replace an “a” with “@,” an “o” with zero, or add an exclamation point at the end.
A longer password creates many more possible combinations.
Think of it like a combination lock. A lock with only a few numbers has far fewer possibilities than one with several. Passwords work much the same way. Every additional character gives an attacker more combinations to work through.
Length helps, but a long password built around personal information can still be easier to guess than you might think.
People often use things that are easy to remember, such as a child’s name, a pet, a favorite sports team, a hometown, a birthday, or the current year.
Something like Buckeyes2026! may meet a website’s requirements for uppercase letters, lowercase letters, numbers and symbols, but it is still fairly predictable. The goal is not simply to make a password look complicated. It is to make it long and difficult to predict.
One way to do that is to use a passphrase.
A passphrase combines several words into something much longer. The words do not need to form a normal sentence. In fact, unrelated words are generally better because they are harder to predict.
When a website allows it, aim for a password or passphrase of at least 15 characters. Longer is even better.
Numbers, capital letters, and symbols are still useful when a website requires them. The key is not relying on complexity alone.
Using long passwords becomes difficult when you have dozens of online accounts. That is where a password manager can help.
Password managers can generate long, random passwords and securely store them so you do not have to remember every one. Many phones, computers, and web browsers now include password-management features, and dedicated password-management services are also available.
Another option becoming more common is the passkey.
Passkeys are designed to replace traditional passwords. Instead of typing a password, you verify your identity using the same method you use to unlock your phone or computer, such as a fingerprint, facial recognition, or device PIN.
Not every website supports passkeys yet, but you may begin seeing the option more often.
Password advice used to sound complicated. Today, the guidance is easier to remember:
A strong password does not have to be impossible for you to remember. It just needs to make an attacker’s job much harder.