The Password Myth: why longer is stronger

For years, most of us were taught the same password rules: Use a capital letter, add a number, throw in a symbol, and change your password regularly.

That advice made passwords look complicated, but it did not always make them much harder for criminals to crack.

Today, cybersecurity guidance has changed. One of the most important things to remember about a password is simple: Length matters.

When we picture someone trying to figure out a password, we may imagine a person typing guesses one at a time. In reality, attackers can use automated tools to test huge numbers of combinations very quickly. They can also start with lists of common passwords, words and predictable patterns people often use.

That means a password such as P@ssw0rd1! may look complicated to us, but it is not especially difficult for a computer to recognize. Attackers already know people commonly replace an “a” with “@,” an “o” with zero, or add an exclamation point at the end.

A longer password creates many more possible combinations.

Think of it like a combination lock. A lock with only a few numbers has far fewer possibilities than one with several. Passwords work much the same way. Every additional character gives an attacker more combinations to work through.

Predictable can still be weak

Length helps, but a long password built around personal information can still be easier to guess than you might think.

People often use things that are easy to remember, such as a child’s name, a pet, a favorite sports team, a hometown, a birthday, or the current year.

Something like Buckeyes2026! may meet a website’s requirements for uppercase letters, lowercase letters, numbers and symbols, but it is still fairly predictable. The goal is not simply to make a password look complicated. It is to make it long and difficult to predict.

Think in phrases

One way to do that is to use a passphrase.

A passphrase combines several words into something much longer. The words do not need to form a normal sentence. In fact, unrelated words are generally better because they are harder to predict.

When a website allows it, aim for a password or passphrase of at least 15 characters. Longer is even better.

Numbers, capital letters, and symbols are still useful when a website requires them. The key is not relying on complexity alone.

Let technology remember for you

Using long passwords becomes difficult when you have dozens of online accounts. That is where a password manager can help.

Password managers can generate long, random passwords and securely store them so you do not have to remember every one. Many phones, computers, and web browsers now include password-management features, and dedicated password-management services are also available.

You may start seeing passkeys

Another option becoming more common is the passkey.

Passkeys are designed to replace traditional passwords. Instead of typing a password, you verify your identity using the same method you use to unlock your phone or computer, such as a fingerprint, facial recognition, or device PIN.

Not every website supports passkeys yet, but you may begin seeing the option more often.

Keep it simple

Password advice used to sound complicated. Today, the guidance is easier to remember:

  • Make it long.
  • Make it unpredictable.
  • Avoid building it around information someone could easily associate with you.

A strong password does not have to be impossible for you to remember. It just needs to make an attacker’s job much harder.