SecurityPasswordsPrivacy2FAWeb Tools

The 2026 Password Security Checklist: 9 Rules That Actually Matter

•By Hamid Abderrahim

Password advice has a reputation for being either obvious ("use strong passwords!") or impossibly vague. The truth is that a handful of evidence-backed rules cover almost all of the real risk. This checklist is ordered by impact — do the first three and you are ahead of most internet users; finish the list and you are ahead of most professionals. Every rule can be checked with free tools, including the Password Generator and Password Strength Checker.

1. Length beats complexity — every time

The math is unforgiving: a random 8-character password with symbols is easier to crack than a random 16-character one with none. Cracking cost grows exponentially with length but only linearly with alphabet size. Modern guidance (NIST 800-63) is explicit: prioritize length, drop the forced symbol rules.

  • Target 16+ characters for anything you care about.
  • 20+ for email and password-manager master passwords.

2. Uniqueness matters more than strength

Password reuse is what turns one website's breach into your breach. Attackers take leaked username/password pairs and spray them across banks, email providers and social networks (credential stuffing) — it is automated, cheap and devastatingly effective against reused passwords. One unique password per account contains any single breach to that account. This is also the strongest argument for the next rule.

3. Use a password manager (and let it generate everything)

Humans cannot remember 80 unique 16-character strings — that is fine, because you are not supposed to. A password manager remembers them; you memorize exactly one strong master passphrase. In-browser generation and storage is a reasonable minimum, but a dedicated manager works across all browsers and phones and handles things like secure sharing and breach alerts. We compared the trade-offs in detail in Password Manager vs Browser Passwords.

4. Build passphrases you can actually type

For the handful of passwords you must type from memory — master passwords, device logins — use a passphrase: 4–5 unrelated words strung together ("granite-cactus-vinyl-obsidian"). Roughly 40+ characters, easy to type on a phone keyboard, far harder to crack than "P@ssw0rd!". The important word is unrelated — famous quotes and song lyrics are in every cracking dictionary.

5. Audit what you already have

Take ten minutes with the Password Strength Checker:

  • Type a variant of your real password, never the exact one you use.
  • Look for the classic failures: dictionary words, years, names, keyboard walks ("qwerty"), reused structures ("Spring2024!" style patterns).
  • Anything scoring weak that guards email or finance gets replaced today.

Note the variant advice — a client-side checker never transmits your input, but typing your actual production password into any website is a habit worth avoiding on principle.

6. Turn on 2FA — and prefer app-based over SMS

A stolen password plus a second factor is usually a stopped attack. Rank the options:

  1. Passkeys / hardware keys — best: resistant to phishing by design.
  2. Authenticator apps (TOTP) — very good, works everywhere.
  3. SMS codes — better than nothing, but vulnerable to SIM-swap attacks.

Start with email, banking, and your password manager. Those three unlock everything else.

7. Your email password is the keystone

Every "forgot password" flow on every other site sends reset links to your email. Whoever controls your inbox can reset your way into nearly everything. It gets the longest passphrase, the strongest 2FA, and never gets reused anywhere.

8. Stop rotating on a schedule — rotate on evidence

The old advice ("change passwords every 90 days") has been retracted by the very standards bodies that issued it: forced rotation pushes people toward predictable patterns ("Spring2024!" → "Summer2024!"). Modern guidance: change a password when there is a reason — a breach notice involving that site, malware on a device, or evidence of unusual logins — not when a calendar page turns.

9. Generate passwords only where they are generated safely

Client-side generation matters. A generated password that transits a server has left your control; one generated in your browser with a cryptographic random number generator (the Web Crypto API) never does. The Password Generator runs entirely in your tab — length, character classes and excluded look-alike characters are all under your control, and nothing is transmitted or logged.

The five-minute version

Short on time? This catches most of the risk:

  1. Install a password manager today.
  2. Replace your email password with a 4-word passphrase + app-based 2FA.
  3. Let the manager generate 16+ character unique passwords for your top ten accounts.
  4. Check old habits with the Password Strength Checker.

Security is not a personality trait — it is a small set of habits. These nine cover the 95% case.

Frequently asked questions

Are passphrases really as strong as random passwords?

Per character, no; per unit of memorability, far better. A 5-word random passphrase has comparable entropy to a 13-character random password and is dramatically easier to type and remember — which is exactly what you want for the few passwords you keep in your head.

Is it safe to type my password into a strength checker?

A genuinely client-side checker processes your input only in your browser. Still, the safest practice is to test a close variant rather than the exact string — the structural weaknesses are the same.

Do I need to change all my passwords after a big breach in the news?

Only if you had an account there — or reused that password elsewhere. That is precisely the reuse trap: one breach becomes thousands of sites' problem. Unique passwords keep it contained.

What is the single highest-impact change?

Enabling app-based two-factor authentication on your email account. It converts the keystone account from "one stolen password away from disaster" to "effectively locked".


Audit your habits now: generate a 20-character password with Password Generator, test a variant of your current one with Password Strength Checker, and read Password Manager vs Browser Passwords to pick your storage setup — all free, all in your browser.