To create a strong password you can remember, build it from four to six completely unrelated random words, then add a couple of numbers and a symbol so it clears any site rule. That gives you something a password cracker struggles with and your brain still holds a month later.
The reason this matters is dull and unglamorous. Password reuse means one site that leaks hands an attacker the key to your email, and then to your bank. And a password you cannot recall is a password you will quietly reset to something weak the third time you mistype it.
The fix is not more willpower at the login screen. It is a method you can repeat in two minutes, plus a place to store what you made. Below is the whole process, including the memorisation step that most guides skip and that forum threads complain about constantly.
Table of Contents
- 1What You Need
- 2Step-by-Step
- 3How to Choose a Memorable Passphrase
- 4How to Make It Stronger Without Making It Hard to Remember
- 5How to Test and Store the Password
- 6How to Create a Different Password for Every Account
- 7Common Mistakes
- 8Frequently Asked Questions
- 9Are passphrases secure or only for people who cannot handle complex passwords?
- 10How long should a password be?
- 11Do I need a password manager?
- 12How do I remember a password without writing it down?
- 13Is a sentence turned into an acronym a good password?
- 14What if I forget my password manager master password?
What You Need
Four things, and you can line them up before you start typing.
- One specific account. Decide which login you are actually setting. A brand new account at a site you already use is the easiest place to practise.
- A short phrase you can picture. A line from a film, something your kid said once, the place you took your first bad photo. Anything with a mental image attached.
- A decision about storage. A password manager, or one secure record you keep offline. Pick this before you create the password, not after.
- Optionally, a password manager. If you do not have one yet, this is the step that makes the rest sustainable. NIST guidance and CISA both recommend using one instead of memorising dozens of strings.
You do not need any special hardware or a paid tool to do this well. Ten minutes and a text editor is enough.
Step-by-Step
How to Choose a Memorable Passphrase

Pick four to six words that have nothing to do with each other. Nothing to do with each other is the whole trick, and it is where most people go wrong.
A themed phrase, like five beach words or five cat breeds, feels random but is not. Attackers know the theme too, and any word list or brute-force run that tries themed combinations will hit it. Unrelated words work because the list of possible combinations is enormous.
Concrete example: Marble Kettle Tuesday Lighthouse. Four ordinary nouns and an ordinary day of the week. No story connects them, which is exactly the point, and it is far easier to recall than P4!nbl73xQ on a bad day.
If you want genuinely random words instead of ones you picked yourself, open the dictionary on a random page and take four words from different lines. Offline, take four words from four different books. If a site offers a passphrase generator built on a published word list, that is the cleanest option of all.
How many words do you actually need? Four is a solid floor for ordinary accounts. Five or six is a better answer for email and banking, where one breach cascades. Someone running a KeePass setup asked whether five or six words was enough for a normal person, and the honest answer is that the real constraint is what else you reuse, not which word you picked.
How to Make It Stronger Without Making It Hard to Remember

Add length first, because length is what does the work. Then add a small number of substitutions, and stop there before the password turns into soup.
Entropy is just a way of saying how many guesses an attacker needs before they land on it. Each extra character multiplies the total number of combinations, which is why a long phrase beats a short complicated one.
| What you type | Approximate guesses to crack |
|---|---|
| 4 random words | about 50 bits |
| 6 random words | about 75 bits |
| 8 random words | about 100 bits |
| 8 mixed characters | about 50 bits |
| 12 mixed characters | about 75 bits |
| 16 mixed characters | about 100 bits |
Read that the honest way. Six words and a 12-character random string land in the same place, but only one of them is a sentence you can picture. Eight words are roughly as strong as a 16-character random string, and still readable.
Then do a few substitutions that do not wreck the picture. Add the year you started something, swap one letter for a lookalike symbol, change a space to an underscore if the site allows it. Example: Marble-Kettle-Tuesday-Lighthouse becomes marble_kettle_Tuesday7_Light-H0use.
What to skip is mangling every vowel into a number. Turning the whole phrase into a string of symbols may add a little strength, but it removes the mental image entirely, and the image was the reason this method works in the first place.
Two practical edge cases come up constantly. Some banks cap length at 20 characters, which is annoying but still workable with four words. Some sites reject spaces outright, and the fix is the same: switch the separators to hyphens or underscores and keep the word count at four or higher.
How to Test and Store the Password
Test it, then put it somewhere safe. In that order.
Most sites and operating systems now show a strength indicator as you type. If the meter reads strong at 16 characters or more, you are in reasonable shape. Do not trust the checkmark on the signup form itself, since plenty of sites accept anything as long as it is eight characters long.
For storage, a password manager is the right answer for anything you care about. You memorise one master password, ideally a five or six word passphrase of your own, and the manager generates and fills a unique password for everything else. The vault is encrypted, autofill stops you typing it wrongly, and you stop reusing passwords by accident.
Two-factor authentication is the companion step. An authenticator app on your phone beats SMS codes, and it means a stolen password alone does not get anyone into your account. Turn it on the same day you set the password, because you will not remember which accounts are still missing it.
Where to avoid storing it: a text file on your desktop, an email draft to yourself, a note in a notes app that syncs to a cloud account, a sticky note on a monitor. Those are all fine places for a password you have already replaced.
Is writing passwords down acceptable? It is far less risky than reusing one weak password across ten accounts. Locked in a safe or stored in a sealed envelope at home, a paper list beats your memory. The old advice came from a time when people shared one computer; that no longer describes most homes.
Before you finish, plan the recovery order while you are still thinking clearly. If you forget the master password, a good manager cannot help you, so know now which email address is on the account, whether you printed a recovery kit, and which second factor you registered. Then review your accounts once a year and any time a service tells you it was breached.
How to Create a Different Password for Every Account
Unique passwords are the goal, and a manager handles it automatically. Without one, you can still vary by account without ending up with four confusing near-identical strings.
The rule is to change a whole word, not one character. Marble Kettle Tuesday Lighthouse for email, Cobalt Harbor Tuesday Lighthouse for your bank, Marble Kettle Tuesday Anchor for a forum. Same shape, obviously different passwords, and each one still tells your brain a small story.
What not to do is increment the end of a single password: Logins1, Logins2, Logins3. Attack tools check exactly that pattern, so it looks unique to you and reads as one password to a cracker.
Shared and work accounts need a separate plan. If someone else needs the login, treat it as a shared secret rather than a personal password, change it when someone leaves the group, and turn on two-factor authentication wherever the service allows it.
Now the part almost nobody covers: how you actually learn the one you just invented. Say it out loud four times. Type it into your phone’s notes app wrong on purpose, then right. Log into the real account today, while it is fresh. Most people fail here because they generate a good passphrase, close the tab, and discover three days later that the words have already blurred together.
Common Mistakes
These are the ones that keep showing up, each with the fix.
- Using names, birthdays or pets. Your social profiles hold the same information, and it gets used first. Fix: keep personal details out of the password entirely.
- Short complex strings. Password1! looks tough and is guessed in seconds because it sits at the top of every cracking list. Fix: length first, complexity second.
- Themed word lists. Five words about your holiday are far less random than they feel. Fix: unrelated words from a generator or four different books.
- Reusing one password everywhere. Fix: one unique passphrase or generated password per account, and let a manager handle it.
- Tiny, obvious tweaks. Cloud12 and Cloud13 are the same password with a countdown. Fix: swap a whole word per account.
- Forgetting the master password with no recovery plan. Fix: register a second factor and confirm your recovery email before you need either.
- Turning every letter into a symbol. It looks stronger and reads worse. Fix: a handful of substitutions, then stop.
- Keeping the note where you found it. A sticky note on the same monitor as the login helps nobody. Fix: locked away, or nowhere at all.
One habit worth keeping: whenever you set a new account, check the password rules on screen first. Some sites cap length at 12 characters, some forbid spaces, and some demand a symbol you do not otherwise use. Reading the rule before you start saves a reset later.
Frequently Asked Questions
Are passphrases secure or only for people who cannot handle complex passwords?
A passphrase of four or more unrelated words is one of the stronger options available, and easier to recall than a random string. Four words sit at roughly 50 bits of difficulty, about the same as an 8-character mixed string, but six words reach roughly 75 bits, which is more than most people expect from something they can picture. The words must be unrelated; a themed set is far weaker.
How long should a password be?
Sixteen characters is the common floor for anything that matters, and longer is better. For banking, email and your password manager master password, aim for four to six unrelated words, which usually runs 20 to 30 characters and is far easier to remember than the same strength in random symbols. Password rules have tightened over the years, so aim at 16 or more and stop worrying about matching every rule exactly.
Do I need a password manager?
If you have more than a handful of accounts, yes. You memorise one master password and the manager creates a unique, random password for everything else, which removes reuse by default and stops you guessing at which variant you used. NIST and CISA both recommend it. The trade-off is that you must pick a master password you will actually remember in five years, and set up recovery options before you need them.
How do I remember a password without writing it down?
Say it out loud several times, type it into the real login within a few minutes, and use it early and often until it is automatic. A password manager is the better answer: the one password you memorise is the master password, and everything else is filled in for you. Writing passwords on paper is also reasonable if the list is locked away, which beats reusing one weak password across ten accounts.
Is a sentence turned into an acronym a good password?
It works when the sentence is personal and unusual, because you remember the source even if you forget the letters. It is weaker than random words because the acronym is short and the pattern is guessable. Use it as a base and add length and substitutions, and never pick a famous lyric or quote, since those sit in every cracking dictionary in the world.
What if I forget my password manager master password?
Assume it is gone, and that is the reason recovery planning matters. Before you forget it, confirm the recovery email on the account, save any printed recovery kit, and register a second factor you control. No reputable manager can reset your master password for you, because that would defeat the point of encryption. If you have no recovery route, start a new vault and change your email password first, since it is the master key to everything else.
Start with one account today, not all of them. Pick four unrelated words, add a number and a symbol, type it into the real login so your brain files it away, then store it in a password manager and turn on two-factor authentication before you close the laptop.


