Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology12 min read

Coming up with a new password doesn't have to be hard – I'm a password expert, and these are my 5 top tips for crafting the perfect password | TechRadar

These are my top tips for creating a good password Discover insights about coming up with a new password doesn't have to be hard – i'm a password expert, and th

TechnologyInnovationBest PracticesGuideTutorial
Coming up with a new password doesn't have to be hard – I'm a password expert, and these are my 5 top tips for crafting the perfect password | TechRadar
Listen to Article
0:00
0:00
0:00

Coming up with a new password doesn't have to be hard – I'm a password expert, and these are my 5 top tips for crafting the perfect password | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Coming up with a new password doesn't have to be hard – I'm a password expert, and these are my 5 top tips for crafting the perfect password

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

(Image credit: Image: Generated with Google Gemini)

In case you weren’t aware, today is World Password Day.

Now, some experts might tell you today that passwords are obsolete and we need to move to new methods of securing accounts. We’re not quite there yet.

It takes time for organizations to make the changes necessary to make passkeys an everyday reality - but until that day comes, we are reliant on passwords.

‘We must do more to protect our credentials’: Password security has barely changed since 2015 — and that's a big problem for everyone

UK security agency officially declares passkeys superior to passwords – passkeys should be the 'first choice' for authentication

It’s time cyber security understood human behavior and acted accordingly

So, in order to help you keep your accounts secure, I thought that I would share my five top tips for choosing a good password as a password expert.

For a long time, you may have been using a password with a near-unrememberable level of complexity. It might have even been more special characters than normal ones. But as we will explore later, complex does not mean more secure.

The typical rule is that longer passwords are more secure than shorter, complex passwords. Password cracking in the modern world, also known as brute-forcing, requires a computer to go through common password phrases and character combinations in order to guess a password.

The longer the password, the more combinations there are to guess. The more combinations, the longer it takes, exponentially increasing as long as you don’t use a password that is just the letter ‘a’ repeated 12 times.

“A one-character password made from lowercase letters would take at most 26 guesses. Adding a second character increases that number to 26 times 26, which is 676 guesses. An eight-character password would take about 200 billion guesses.”

The recommended length for a password in 2026 is at least 15 characters.

Some top password managers can be hacked and hijacked to change your passwords - here's what we know

AI-generated passwords aren't as secure as they appear

Authentication in 2026 - moving beyond foundational MFA to tackle the new era of attacks

One of the best ways to create a secure password is to link a chain of random words. This makes your password not only memorable, but also long enough to be secure.

For example, NIST guidance uses the example of ‘cassette lava baby’, which is 18 characters long, meaning it will survive 29,479,510,200,013,918,864,408,576 guesses if it is just made of regular lower case characters.

Add in some capitals and special characters, that number gets way bigger.

Flick to a few random pages in a dictionary, choose a few words, and link them together. Boom, you now have your next password.

Special characters do add an extra level of complexity to a password, especially if it is a human trying to guess. But they can create predictable patterns.

For example, many people replace regular characters with special characters in recognizable ways. For example, replacing the letter ‘S’ with ‘$’, or ‘A’ with ‘@’. This is especially true when it comes to my next point.

Including special characters does increase the number of possible combinations, but don’t put them in predictable places.

Your organization may enforce password changes every 90 days. But this can push employees into bad habits. We are simple creatures, and we like things to be easy. That’s why when a password change is enforced, we will do as little as possible to change it.

It might be as simple as changing the combination of numbers at the end, or choosing the next in a series of words, such as switching from ‘Monday 1234’ to ‘Tuesday 1234’. This means that even if the first password is exposed in a data breach and your password is changed to the second one, it gives an attacker a pretty good guess at what the next combination could be.

A top tip for organizations that comes straight from NIST: Don’t enforce password changes unless there is evidence of a breach. It frustrates employees and makes them more likely to choose weak combinations.

Wherever possible, you multi-factor authentication to secure your accounts. Authenticators help protect accounts by acting as a second method of verification.

So, wherever possible, use multi-factor authentication to keep your accounts as secure as possible.

In conclusion, these are the key tips to making a secure password and keeping your account secure:

Always use a unique password if you are forced to change it

Password managers are excellent tools for securely managing and storing your passwords. They can suggest new passwords using the latest guidance and automatically store and auto-fill them to save you time.

Password managers aren’t just a place to store them. Many password managers offer dark web monitoring to check for breaches and exposed credentials. You can also check your own credential exposure using a service such as Have I Been Pwned.

Audit your own credentials. Delete any accounts you no longer use. Not only can they expose your credentials, but the companies you have signed up with can sell or pass on your information to third-parties, putting them at a greater risk of exposure.

Stay up to date with the latest guidance from NIST.

As it is World Password Day - the industry's top experts have been offering advice to help businesses and individuals stay secure, and I've rounded up some of the best advice from the experts to help secure your accounts.

Adrian Podkaminer, Head of Security at G2A. COM says:

"As World Password Day approaches, it is a timely reminder that in today’s digital economy, where gaming, commerce, and payments all happen online, protecting digital identity is central to security. Recent industry reporting shows that compromised credentials and other identity-based attacks remain among the most common paths to account compromise and broader security incidents.

Weak or reused passwords are still one of the primary attack vectors, but the threat landscape is also evolving through AI-enabled phishing and social engineering. Threat actors are increasingly using generative AI to scale credential-harvesting campaigns, create more convincing impersonation attempts, and produce fraudulent communications that are harder to distinguish from legitimate ones. AI does not fundamentally change how passwords are cracked; it makes stealing them through deception more efficient.

Threat actors are increasingly using generative AI to scale credential-harvesting campaigns

Threat actors are increasingly using generative AI to scale credential-harvesting campaigns

At G2A, we follow “Zero Trust” principles alongside real-time fraud detection, secure payment controls, seller verification and marketplace risk controls. Cybersecurity is a shared responsibility and a continuous process, not a static destination. World Password Day is a useful reminder that both platforms and users need to keep strengthening how they protect accounts and digital identity."

Steven Furnell, senior IEEE member and professor of cybersecurity at the University of Nottingham says:

“The NCSC’s recommendation to use passkeys 'wherever a service supports them' is good from both security and usability perspectives. Passkeys have been specifically designed to overcome our primary problems with passwords.

It’s still the correct advice, but no matter how good passkeys are, we need to recognise that this is going to be a long game rather than flipping a switch.

No matter how good passkeys are, we need to recognise that this is going to be a long game rather than flipping a switch

No matter how good passkeys are, we need to recognise that this is going to be a long game rather than flipping a switch

Where passwords are still in use, it’s far too easy to find sites that fail to support the user in two significant and fundamental ways, by asking them to create new passwords while providing little or no tangible guidance on how to do so securely, and/or allowing them to get away with making choices that would generally be regarded as weak.

While some might argue that it’s the user’s responsibility to protect themselves properly, they need to know how to do it. Where are they supposed to get this knowledge if the sites don’t offer it? Why would the user even suspect there’s a problem if the site lets them choose a poor password without complaint?

This World Password Day, the main message ought not to be to the users, who often have no choice but to use passwords anyway, but to the sites and providers that are requiring them to do so.”

“The most effective password may be no password at all. World Password Day has started to feel ironic because most people already know that passwords are a problem. We’ve spent years telling users to create longer passwords, avoid reusing them, rotate them regularly, and add more layers of authentication on top, but the reality is that passwords still create friction for users and opportunity for attackers. We’ve all been there – people forget them, reuse them, write them down, or work around security policies altogether because the process of managing passwords effectively feels admin-heavy. For years now organizations have been moving toward passwordless authentication like on-device biometrics, and more recently passkeys. If the number one goal is security, we have to reduce our reliance on a system that was never really designed for the way we work today.

The most effective password may be no password at all

The most effective password may be no password at all

Passkeys are a step up because they improve security while at the same time making authentication feel more natural for users. Instead of having to remember a convoluted password, passkeys allow authentication to be tied to a user’s device or their own biometric signals, such as a fingerprint, facial recognition, or device-based credential. With passkeys, we’re finally starting to see authentication move to where it should be – a seamless process that doesn’t interrupt your flow every time you launch an app.

Having said that, passwords aren’t going to disappear overnight. Most companies are still operating across a mix of legacy systems and unmanaged devices, so the full transition to passkeys will happen gradually – but it will happen. In many ways, passwords are starting to feel like a set of physical keys we have to carry – just like physical keys, you need a different one for every digital service you use. They’ve been with us for decades, so they’re accepted as normal, but that doesn’t make them the best fit for how we work today. World Password Day exists to raise awareness about good password hygiene and security practices, but as security becomes more of a fluid, embedded, background process, the need to raise awareness will diminish – because security will simply be designed into whatever process we’re using.

Next year, rather than reminding people to manage passwords better, we should celebrate a future without them.”

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Benedict is a Senior Security Writer at Tech Radar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.

Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.

You must confirm your public display name before commenting

1'A Lego brick that plays music': A great Scandi loudspeaker brand returns with 7 new products, including a shallower option designed for narrow bookshelves

2'A waste of money' — Digital rights group slams Utah's new 'impossible by design' VPN restrictions under controversial age verification law

3RGG Studio's Stranger Than Heaven is seemingly the most original action-RPG I've seen yet: here are four ways it stands out from others

4 Palo Alto warns of critical firewall flaw, tells users a patch is on the way

5 Budget Windows 11 laptops vs Mac Book Neo — Microsoft-commissioned report points out Neo weaknesses, as Apple's rumored to double production to 10 million

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.