โ† Blog

7 min read

Need Help With Your Passwords?

What makes a password strong, what to avoid, and how to stop trying to remember them all

A close-up of a padlock resting on a laptop keyboard, representing password and account security
โ† Back to all articles
Text size:

Many people use the same few passwords for years โ€” sometimes the same one everywhere. It's understandable. Nobody can realistically memorize twenty different combinations of letters, numbers, and symbols. But there's a middle path between "impossible to remember" and "easy to guess," and a tool that solves the whole problem once and for all.

This article covers what actually makes a password strong, the most common mistakes, and what to do if keeping track of it all has become too much.


What Makes a Password Strong?

The most important thing about a password isn't how complicated it looks โ€” it's how long it is. Length is the single biggest factor in how hard a password is to crack. A 16-character password made of ordinary words is stronger than an 8-character jumble of symbols.

The most common weak passwords are things like your name, your spouse's name, a pet's name, your birthday, your phone number, or the word "password" itself (including variations like "Password1" or "Password123"). Simple number sequences like "12345678" and keyboard patterns like "qwerty" are also on every hacker's list. If any of your current passwords look like that โ€” especially on important accounts โ€” it's worth changing them.

Try a passphrase instead

One practical approach: string together three or four unrelated words. Something like maple lamp orange boots is easier to remember than a short tangle of symbols, and it's actually stronger โ€” because it's much longer. You could imagine a little scene to help it stick, or just say it to yourself a few times when you create it. The words don't need to make sense together; in fact, it's better if they don't.


The Biggest Risk: Using the Same Password Everywhere

Even a strong password becomes a problem when you use it on multiple accounts. Here's why: companies get hacked regularly, and when they do, the stolen information โ€” including account credentials โ€” can end up for sale or circulating online. This is called a data breach, and it happens to large, reputable companies as well as small ones.

If you used the same password on a store's website that later got hacked as you did on your email account, whoever got that password now has access to your email. And your email is the key to almost everything else โ€” because most accounts let you reset your password by sending a link to your email address.

Using different passwords for different accounts is the single most effective thing you can do to protect yourself online.


Four Things Worth Doing

1

Make it long

Aim for at least 12 characters. A passphrase โ€” three or four unrelated words strung together โ€” works well and is far easier to remember than random symbols. Length matters more than complexity.

2

Use unique passwords on your important accounts

Your bank, your email, and any account connected to a credit card should each have its own unique password. If one gets compromised, the others stay safe.

3

Never share your password

A password is private โ€” not just from strangers, but ideally from everyone. No legitimate bank, government office, or tech company will ever call and ask for your password. If someone does, that's a red flag.

4

Use your browser's built-in password manager

Your browser โ€” whether that's Chrome, Safari, Firefox, or Edge โ€” already has a password manager built right in. It can create a strong, unique password for you when you sign up for something new, save it automatically, and fill it in the next time you need it. Because it's already part of what you're using, there's nothing extra to download or learn โ€” it's the most straightforward option for most people.


Where Not to Keep Your Passwords

โš  Watch out

A sticky note attached to your computer โ€” or a notebook left open on your desk โ€” puts your passwords in plain view of anyone who visits. Writing passwords down isn't wrong on its own; the problem is leaving them somewhere visible.

If you keep a written list, store it somewhere private: a locked drawer, a safe, or a notebook you keep tucked away โ€” not near your computer. And try to write down a reminder or hint rather than the full password where you can.


An Extra Layer: Two-Factor Authentication

Even with a strong password, it's worth knowing about two-factor authentication โ€” sometimes called 2FA or "two-step verification." When it's turned on, signing in to your account requires two things: your password, and a short code sent to your phone. Even if someone gets hold of your password, they still can't get in without that code.

Many banks and email providers offer this, and some require it. If you've ever received a text with a 6-digit code when logging into something, that was two-factor authentication at work.


What to Do If You Think Someone Got In

If you notice something unusual โ€” emails you didn't send, changes you didn't make, a login alert from a new location, or an account that won't accept your password โ€” act quickly:

โœ“ An easier way

If remembering different passwords for every account feels impossible โ€” it is, for most people. The easiest solution is the one already built into your browser. Chrome, Safari, Firefox, and Edge all include a password manager that creates strong passwords for you, saves them, and fills them in automatically. There's nothing extra to set up โ€” it's already there. That's the one I'd recommend starting with.


A Note

Password recommendations and available tools change over time. This article reflects general best practices as of August 12, 2026. The built-in password manager in your browser is the starting point I'd recommend for most people โ€” but which browser you use and how it's set up on your device can vary.

In-home visits ยท Computers, phones & tablets ยท Software only โ€” hardware repairs referred out ยท Service agreement signed before we begin ยท I am not a certified technician; I provide support based on experience and knowledge ยท Canadian Anti-Fraud Centre 1-888-495-8501