Why Your Password Probably Isn't Safe
The most common passwords in the world are still "123456," "password," and "qwerty." But even people who think they have strong passwords often don't. If your password is a word with a number at the end (like "Summer2024"), a pet's name, or your date of birth, it can be cracked in seconds by modern software.
Password-cracking tools can try billions of combinations per second. They start with common words, names, dates, and known patterns. A password like "Michael1985!" feels strong but follows a predictable pattern that cracking tools are specifically designed to break.
The length of a password matters more than its complexity. A 16-character password made of random words is much harder to crack than an 8-character password full of symbols.
The Passphrase Method
The easiest way to create a strong, memorable password is to use a passphrase — a string of four or more random words. For example: "correct horse battery staple" (this famous example from a webcomic is actually good advice).
Pick four or five words that don't naturally go together. You can make it even stronger by adding a number or symbol between them.
- Pick 4-5 random, unrelated words. Example: "purple umbrella fishing tuesday"
- Make it personal but not guessable. Avoid family names, birthdays, or favourite things that appear on your social media.
- Add a number or symbol if you need to meet password requirements: "purple-umbrella-fishing-42"
- The result is long (very hard to crack), memorable (easy for you to recall), and unique.
Password strength comparison
The password "P@ssw0rd!" has 9 characters with symbols and numbers. It can be cracked in under 1 second because it's in every password dictionary. The passphrase "orange-bicycle-rainbow-17" has 26 characters and would take centuries to crack by brute force, yet it's much easier to remember.
The Golden Rule: Never Reuse Passwords
Using the same password on multiple websites is the single most dangerous password habit. When a company gets hacked (and they do, regularly), the stolen passwords are tested on every other major website.
If your Facebook password is the same as your email password, and Facebook gets breached, the hackers now have access to your email. And with your email, they can reset passwords on everything else.
Data breaches happen constantly. In 2023 alone, over 8 billion records were exposed in data breaches worldwide. If you reuse passwords, a breach at any one of those companies could compromise all your accounts.
What About Writing Passwords Down?
Cybersecurity experts used to say "never write your passwords down." That advice has changed. It's actually better to write down unique passwords and keep them somewhere safe than to reuse the same weak password everywhere.
A piece of paper in a locked drawer is quite secure — online criminals can't access it. Just don't stick it on a note attached to your monitor or keep it in your wallet.
A password written in a notebook at home is safer than the same password used on 20 different websites. The real risk is online reuse, not physical notes.