In 2003, a NIST employee named Bill Burr wrote an appendix recommending passwords with mixed case, numbers and symbols, changed every 90 days. It became the rule nearly every organisation enforced for the next fifteen years.
In 2017, NIST formally withdrew it. Burr himself said publicly that he regretted it. The guidance had produced exactly the wrong outcome: people responded to complexity rules with predictable substitutions, and to rotation rules by incrementing a number.
P@ssw0rd1 satisfies every one of those requirements and is cracked instantly, because every attacker's rule set expands those substitutions automatically.
Length beats complexity, by a lot
Each additional character multiplies the search space. Each additional character type only widens the base. Length wins decisively.
Using all four character types (95 possible characters per position):
| Length | Entropy | Verdict |
|---|---|---|
| 8 characters | ≈ 52 bits | Crackable by a well-resourced attacker |
| 12 characters | ≈ 79 bits | Reasonable for most accounts |
| 16 characters | ≈ 105 bits | The sensible current minimum for anything important |
| 24 characters | ≈ 158 bits | Beyond any foreseeable brute-force capability |
Entropy is measured in bits, and each bit doubles the number of guesses required. The jump from 8 to 16 characters is not twice as hard — it is roughly 2⁵³ times as hard.
What NIST recommends now
- Minimum 8 characters, support at least 64. Let people use long passphrases.
- No composition rules. Do not require a symbol. It produces predictable patterns.
- No forced periodic rotation. Change passwords when there is evidence of compromise, not on a calendar. Forced rotation produces
Spring2026!followed bySummer2026!. - Check against known breached passwords. This is the single highest-value check, and it replaces complexity rules entirely.
- Allow all characters, including spaces and emoji. Restricting the character set only reduces entropy.
- Allow paste. Blocking it actively prevents password manager use, which makes security worse.
Randomness has to be real
A generated password is only as unpredictable as the source it came from.
Browsers expose two: Math.random() and crypto.getRandomValues(). The first is fast and statistically fine for shuffling a list — and predictable enough that an attacker who observes some output can infer the rest. Password generators built on it have been broken in practice.
crypto.getRandomValues() is a cryptographically secure generator, the same primitive used for TLS key material. That is what our password generator uses, and it is worth checking which source any generator you rely on is built on.
The three things that matter more than strength
A strength meter measures structure. It cannot see the three failures that actually compromise accounts.
1. Reuse. A 20-character random password used on five sites is only as safe as the least secure of those five. Credential stuffing — replaying credentials from one breach against other services — is among the most common attack methods precisely because reuse is so widespread. One breach then compromises everything sharing that password.
2. Phishing. Password strength is entirely irrelevant if you type it into a convincing fake login page. No amount of entropy helps. This is why phishing-resistant second factors matter more than password complexity.
3. Storage. If a service stores passwords badly, yours is exposed regardless of how strong it was. You cannot control this — which is another argument for unique passwords everywhere, so the blast radius is one account.
Hashing is not encryption, and plain hashing is not storage
Worth stating because the mistake is still widespread in new code.
A plain SHA-256 of a password is not safe storage. SHA-256 is designed to be fast — a modern GPU computes billions per second. Given a stolen hash table, weak passwords fall almost immediately. Unsalted hashes are additionally vulnerable to precomputed rainbow tables, and identical passwords produce identical hashes, which leaks information about your users.
Password storage needs a deliberately slow, salted algorithm built for the job: bcrypt, scrypt or Argon2. Each has a tunable work factor so you can keep it slow as hardware improves.
Our hash generator is for checksums and integrity verification — not for passwords.
What to actually do
- Use a password manager. Bitwarden is free and open source; 1Password and the built-in managers in Apple and Google accounts are all fine. This single change removes reuse entirely and is worth more than everything else on this list.
- Generate unique random passwords for every account. You will never type most of them.
- Memorise exactly two things: your device login and your password manager's master password. Make both passphrases — four or five random words give strong entropy and are far easier to recall than a random string.
- Turn on two-factor authentication, prioritising email, banking and the password manager itself. An authenticator app beats SMS, which is vulnerable to SIM swapping.
- Check your addresses against Have I Been Pwned. It uses k-anonymity, so you never transmit a full password.
- Move to passkeys where offered. They are phishing-resistant by design — the credential is bound to the real domain and simply will not work on a lookalike.
On passphrases
For the two passwords you must memorise, a passphrase is the right answer. Four random words from a large list — correct-horse-battery-staple, to use the famous example — gives around 44 bits of entropy from a 7776-word list, and five words gives 64.
The critical word is random. Words you chose yourself, or a phrase from a song, have far less entropy than the word count suggests, because human choice is not uniform. Use dice or a generator, not your imagination.
Frequently asked questions
How long should a password be?
At least 16 characters for important accounts, 20 or more for anything critical such as your email or password manager master password. Length contributes far more than character variety.
Should I change my passwords regularly?
No. NIST withdrew that advice in 2017. Forced rotation produces predictable increments. Change a password when there is evidence of compromise.
Is it safe to store passwords in a password manager?
Yes, and it is substantially safer than the alternative. A manager removes reuse, which is the single biggest real-world risk. The vault is encrypted with a key derived from your master password.
Can I use SHA-256 to store passwords?
No. It is far too fast — a GPU computes billions per second. Use bcrypt, scrypt or Argon2, which are deliberately slow and salted.
Are passkeys better than passwords?
For the accounts that support them, yes. Passkeys are phishing-resistant by design because the credential is bound to the real domain and will not work on a lookalike site.
Everything on ToolYard runs in your browser. No uploads, no accounts, no limits.
Browse all tools →