ENES
securityEngineering Guide

How to Generate a Secure Password You'll Actually Remember

AS
Published on 2026-10-10Β·11 min readΒ·Daily Toolbox Engineering

How to Generate a Secure Password You'll Actually Remember

Your company's password policy demands 12 characters, uppercase, lowercase, a number, and a symbol. So you create P@ssw0rd123!. It passes the policy check. It would also fall to a dictionary attack in seconds β€” it's just "password" with the most predictable substitutions (@ for a, 0 for o) and the most predictable suffix (123!).

Meanwhile you have 87 other accounts. You reuse three password variations across all of them because remembering 87 unique strings is impossible. One breach, and the attacker has the keys to everything.

There's a better way. It starts with understanding what actually makes a password strong β€” the math, not the policy checkbox.

The Math: Entropy Is What Matters

Password strength isn't about character types. It's about entropy β€” the number of guesses an attacker needs, measured in bits. The formula:

entropy = length Γ— log2(character set size)

A few concrete numbers:

Password Charset Length Entropy Crack time (offline, fast hash)
P@ssw0rd123! ~70 chars 12 ~73 bits theoretical, ~20 bits practical* Seconds (dictionary)
Tr7$kQ9!mZ2@ ~70 chars 12 ~73 bits Centuries (brute force)
correct horse battery staple ~7776 words 4 words ~52 bits Centuries (brute force)
correct horse battery staple extra ~7776 words 5 words ~65 bits Effectively never

*Theoretical entropy assumes random characters. P@ssw0rd123! isn't random β€” it's a dictionary word with predictable substitutions, so its practical entropy is far lower. This is the critical distinction password policies miss.

The takeaway: length beats complexity. A 25-character passphrase of plain words is stronger than a 12-character soup of symbols β€” and you can actually remember it.

Method 1: The Passphrase (Best for Humans)

This is the approach security researchers have recommended for years, and it's finally going mainstream.

How it works:

  1. Pick 4–5 random words from a word list. Not a sentence that makes sense β€” random words. "correct horse battery staple" works because the words are unrelated; "my dog likes treats" doesn't, because it's grammatically predictable.
  2. Join them with a separator: spaces, hyphens, or just smash them together.
  3. Optionally capitalize one word or add a number for sites with annoying complexity requirements.

Concrete example:

Take the Diceware word list (7,776 common English words, each mapped to a dice roll). Roll five dice four times, look up each result:

  • Roll 1: correct
  • Roll 2: horse
  • Roll 3: battery
  • Roll 4: staple

Your password: correct-horse-battery-staple

That's 4 Γ— log2(7776) β‰ˆ 52 bits of entropy. An attacker guessing a billion times per second would need about 140,000 years. And you can remember it after typing it three times.

Need 5 words for extra margin? Add one more roll: correct-horse-battery-staple-extra β†’ ~65 bits. Now you're beyond what any brute-force attack can touch.

Where to get the word list: the EFF's word lists are the standard. Don't use song lyrics, quotes, or Bible verses β€” those are in every attacker's dictionary.

Method 2: Random + Password Manager (Best Overall)

If you use a password manager (Bitwarden, 1Password, KeePassXC β€” all solid), you don't need to remember passwords at all. Generate maximum-entropy random strings and let the manager handle them:

K7$mQ9!vZ2@pL4#nX8&dF5

20 characters from a 70-character set = ~122 bits. That's not just strong β€” it's overkill in the best way. You'll never type it by hand, so memorability is irrelevant.

You only need to remember two things:

  1. Your password manager's master password β€” use a 5-word passphrase (Method 1)
  2. Nothing else. That's the point.

This is objectively the strongest setup. The passphrase protects the vault; the vault holds uncrackable random passwords for everything else. If you're not using a password manager yet, this is the single highest-impact security change you can make.

Method 3: The Hybrid (For Passwords You Type Often)

Some passwords you type daily β€” your laptop login, your password manager master password. For these, pure random strings are painful. Use a hybrid:

  1. Start with 3 random words: ocean-bridge-lamp
  2. Add a personal-but-not-obvious anchor: a number that's meaningful to you but not your birthday (ocean-bridge-lamp-47)
  3. Optionally transform one word: ocean-bridge-lamp47!

The result is memorable (you can picture an ocean, a bridge, a lamp) but not guessable (no attacker knows your anchor number or which words you picked).

What NOT to use as an anchor: birthdays, anniversaries, pet names, addresses, phone numbers. All of these are either public or easily discoverable. Pick something arbitrary β€” the number of books on your shelf, a random page number, anything without a paper trail.

What About Those Complexity Requirements?

Some sites still demand "one uppercase, one number, one symbol." This is outdated advice (NIST dropped it from their guidelines in 2017), but you're stuck with it on those sites. The pragmatic approach:

  • Take your passphrase: correct-horse-battery-staple
  • Capitalize the first letter: Correct-horse-battery-staple
  • Swap the last separator for a number + symbol: Correct-horse-battery9#

You've satisfied the policy without meaningfully weakening the password. The entropy barely changes because the core β€” four random words β€” is doing all the heavy lifting.

Common Mistakes

"Clever" character substitutions. P@ssw0rd isn't clever. Attackers have used a→@, e→3, o→0, s→$ in their dictionaries for 20 years. Every substitution you can think of is already in the attacker's wordlist. Randomness beats cleverness, always.

Reusing passwords across sites. This is the mistake that causes the most real-world damage. When Site A gets breached (and it will β€” breaches are a matter of when, not if), attackers try your email + password on every major site automatically. This is called credential stuffing, and it's fully automated. Unique passwords per site aren't optional.

Password rotation policies. "Change your password every 90 days" sounds secure but backfires. Research shows it leads to weaker passwords β€” people just increment a number (Spring2026! β†’ Summer2026!). NIST now recommends against forced rotation. Change passwords when there's a breach, not on a schedule.

Security questions as backup. "What was your first pet's name?" is not security β€” it's a second, weaker password that's often publicly known. If a site forces security questions, treat the answers as additional passwords: generate random strings and store them in your password manager. "Mother's maiden name: X7#kP2$mQ9!" is perfectly fine.

Writing passwords in a notes app or spreadsheet. An unencrypted notes file is barely better than a sticky note. If you must write them down (and for a password manager master password, a paper backup in a safe is actually reasonable), use paper, not a cloud-synced notes app.

Trusting "password strength meters." Most strength meters just count character types and length. They'll rate P@ssw0rd123! as "Strong" because it has all four character types. It isn't. Strength meters can't detect dictionary patterns. Ignore them.

Passwords Are Only Half the Story: Enable 2FA

Even the strongest password can be phished, keylogged, or leaked in a breach. Two-factor authentication (2FA) adds a second barrier: something you have (your phone) in addition to something you know (your password).

Not all 2FA is equal:

Method Security Notes
Hardware key (YubiKey) Highest Phishing-resistant. The gold standard.
Authenticator app (TOTP) High Codes change every 30 seconds. Works offline.
SMS codes Low Vulnerable to SIM swapping. Better than nothing.
Email codes Low If your email is compromised, so is this.

The priority order: enable 2FA on your email first (it's the recovery point for everything else), then banking, then password manager, then everything else. An authenticator app takes 30 seconds to set up per site and blocks the vast majority of account takeover attempts.

SMS 2FA gets criticized, and rightly β€” SIM swapping attacks are real. But SMS 2FA still blocks automated credential stuffing, which is the most common attack by volume. If SMS is your only option, use it. Don't let perfect be the enemy of good.

The Future: Passkeys

Passkeys (FIDO2/WebAuthn) are the industry's answer to passwords. Instead of a shared secret, your device generates a cryptographic key pair: the public key goes to the site, the private key stays on your device, protected by biometrics or a PIN.

Why they're better:

  • Phishing-resistant. The private key never leaves your device and is bound to the site's domain. A fake login page can't trick it.
  • Nothing to remember. No passwords to generate, store, or type.
  • No server-side secrets. Breaches leak public keys, which are useless to attackers.

The catch: adoption is still ramping up. Not every site supports passkeys yet, and cross-device sync (getting your passkeys onto a new phone) is still maturing. Use passkeys where offered β€” Google, Apple, GitHub, and others support them now β€” but keep your password manager for everything else.

Passkeys won't kill passwords overnight. But they're the direction things are moving, and enabling them where available is strictly an upgrade.

How to Actually Migrate: A Practical Plan

Knowing what to do and doing it are different things. Here's a weekend migration plan:

Saturday morning (1 hour): Pick a password manager and set it up

  1. Install Bitwarden (free, open source) or 1Password (paid, polished). Both work on every platform.
  2. Create your account with a 5-word passphrase as the master password. Write it on paper, store it somewhere safe.
  3. Enable 2FA on the password manager itself β€” authenticator app, not SMS.
  4. Install the browser extension.

Saturday afternoon (2 hours): Migrate your critical accounts Start with these five, in order:

  1. Email β€” the master key to all password resets. Unique 20-character random password + 2FA.
  2. Banking / financial β€” unique random password + 2FA.
  3. Password manager β€” already done, but verify 2FA works.
  4. Cloud storage (Google Drive, iCloud, Dropbox) β€” unique random password + 2FA.
  5. Social media β€” unique random password + 2FA where available.

For each: log in, go to security settings, generate a new random password in your manager, save it, enable 2FA. The manager's browser extension auto-fills from here on.

Sunday (1 hour): Bulk-migrate the rest Go through your remaining accounts. For each one, generate a unique random password. You don't need to do all 87 in one sitting β€” do 20 per weekend and you'll be done in a month. Prioritize anything tied to money, identity, or work.

Ongoing: when you create a new account, let the password manager generate the password. Never type a password by hand again (except your master passphrase).

Total time investment: ~4 hours. What you get: every account protected by a unique, uncrackable password, with 2FA on the important ones. That's a bigger security upgrade than most companies achieve with six-figure budgets.

Try It

You don't need to roll dice or memorize word lists to get started. DailyToolbox's free password generator runs entirely in your browser β€” generate cryptographically random passwords or memorable passphrases, customize length and character sets, and copy with one click. Nothing is sent to a server or stored anywhere, which is exactly how a password tool should work.

πŸ‘‰ Try the Password Generator β†’

FAQ

How long should my password be? For random passwords: 16+ characters. For passphrases: 4+ words (5 is better). These give you 80+ and 52+ bits of entropy respectively, both well beyond brute-force range. Longer is always better β€” there's no downside to a 6-word passphrase except typing time.

Are password managers safe? Can't they get hacked? Reputable password managers (Bitwarden, 1Password, KeePassXC) encrypt your vault locally with your master password before anything touches their servers. Even if their servers are breached, the attacker gets encrypted blobs they'd need your master password to decrypt. This is vastly safer than reusing passwords. Use a strong master passphrase and enable 2FA on the manager itself.

What if I can't use a password manager (work computer, shared device)? Use passphrases (Method 1). Four random words are typeable, memorable, and strong enough for any account. For your most critical accounts (email, bank), use 5 words. Your email is the most important β€” password resets go there, so it's the key to everything else.

Do I really need unique passwords for every site? Yes. Credential stuffing is automated and relentless β€” breached credentials are tested against hundreds of sites within hours. A password manager makes unique passwords effortless. Without one, at minimum use unique passphrases for email, banking, and anything tied to your identity or money.

#security#passwords#webdev#tutorial
AS
Written by Alex Sun

Alex Sun is the developer behind Daily Toolbox. He writes these guides while building the tools themselves β€” every claim tested against the real thing.

Try the free tools mentioned above

Try it free β†’