Skip to content
IT

How to create a strong password you can actually remember

No weird formulas: a three-step method to invent long passwords, different for every site and easy to keep in mind. With examples.

Tecnonota Staff · · 3 min read

Cyber for Humans
Level
beginner
Time
10 minutes
What you need
Pen and paper, or your phone

If you use the same password for your email, your bank and the site where you buy shoes, you’re not alone: more than half of people do. The problem is that when one of those sites gets “hacked” (it happens often, even to the big ones), that password ends up in lists that scammers try on every other site. In this article we’ll see how to create a good one, with a method that works even if your memory is poor.

In plain words

Password: the secret word that proves to a website that it's you. Data breach: when someone steals a website's archive, passwords included. You can check whether your email has been in a breach on the free site haveibeenpwned.com.

What makes a password strong (and what doesn’t)

The two things that really matter are length and being different for every site. Swapping an “a” for an “@” or adding an exclamation mark at the end helps very little: the programs that try to guess passwords know all those tricks. An 8-character password with symbols can be guessed in a few hours; 16 ordinary letters take centuries.

The method in three steps

  1. Make up a sentence of your own. Four or five words that mean something to you but nobody could guess, with no spaces. Example: GrandmaMakesRagùOnSaturdays. It's long (27 characters), easy to remember because it's a picture, and impossible to find in a dictionary.
  2. Add a bit tied to the site. For email: GrandmaMakesRagùOnSaturdays-mail. For the bank: GrandmaMakesRagùOnSaturdays-bank. Every site gets a different password, but you only need to remember one sentence.
  3. Change the base sentence only for the important accounts. For your main email and your bank use a completely different sentence from the others. Those are the two accounts that, if stolen, let someone steal everything else.
Don't worry:

You don't need to change passwords every month. That advice is outdated: change one only if you suspect someone has discovered it, or if the site warns you about a breach.

Where to keep them

Writing them in a notebook kept at home is not wrong at all: a password thief is on the other side of the world, not in your drawer. The modern alternative is a password manager: an app that remembers them for you and fills them in automatically. Your phone already has a free one (Google Password Manager on Android, iCloud Keychain on iPhone): when you create an account it suggests a long password and saves it. From then on you only need to remember your phone’s unlock code.

Two mistakes to avoid

Don’t use information that can be found on social media: the dog’s name, your birthday, your football team. And never give your password to anyone who asks for it by phone or email, even if they say they’re the bank: the bank never asks, for any reason.

The next step

Once your passwords are sorted, the biggest improvement is turning on “two-step verification” on your email and your bank. That’s the next article in this column: Two-step verification: what it is and how to turn it on.

More in Cyber for Humans