Passwords

How to create a secure password without making it complicated

A good password does not need to look impossible to read. What matters is that it is long, hard to predict, unique to each account and easy to store safely.

Gráfico de una contraseña larga con un candado

Length matters more than tricks

Current NIST guidance gives length a central role and discourages artificial composition rules such as always forcing a particular mix of character types. For passwords used as a single factor, NIST sets a 15-character minimum and recommends that services allow at least 64. A randomly generated password can take advantage of that length without requiring you to memorize it.

If you need to remember it, use genuinely random words

Passphrases made from several random words can be easier to remember than a string of symbols. The key is that the words must not form a familiar phrase or relate to you. “light-sun-forest-piano-trail-cloud” is a better idea than combining your name, favourite team, pet or year of birth. The Rusadix generator selects words randomly in the browser and does not use personal data.

Related toolCreate a password using these criteria
Open password generator
Avoid predictable patterns

123456, qwerty, name + year, dates, phone numbers, licence plates, pets, teams, single dictionary words and obvious substitutions such as replacing an “o” with zero.

One account, one password

Reusing a password turns one isolated problem into several. If a credential is exposed at one service, the same combination can be tried automatically elsewhere. The most effective measure is to give every account a different password. A password manager makes this practical by storing long, unique passwords without requiring you to remember all of them.

How to store a password

If a tool generates the password, copy it directly into a password manager and let the manager fill it when needed. For the manager's own master password, a long random-word passphrase can be easier to handle. If a service offers two-step authentication or a passkey, enable it: that adds protection that does not rely only on the password.

You do not need to change it on a schedule

Changing a password every few weeks does not make it better by itself and can encourage predictable variations. Current NIST guidance is not to require periodic changes without a reason. It should be changed if there is evidence of exposure, if you reused it or if the service warns you about an incident.

Reference sources