I'm curious to know how strong people make their passwords these days. What's typical for you? I'll go first.

For important things, it's 20+ characters and if that's not possible, then the maximum supported length. This includes passwords that I memorize.

For just the standard accounts, usually 12 characters. But I'm probably going to crank that up just for funsies.

It's just annoying to type in 32 characters of complete line noise in those rare circumstances where I have to do so for some reasons.

#cybersecurity #security #infosec

Reply to this note

Please Login to reply.

Discussion

Most of my passwords are 10+ characters with number, lower and capital cases following a somewhat pattern. not super safe. the super safe ones are on my sovereign stack only.

8 EFF long-list words seperated by a special character.

Why aren't you using a password manager?

I am, but sometimes I only have my phone with me and need to type in a password on a computer

30-40 random characters. If its something I might have to manually type in, then its a generated passphrase.

Usually I'm generating 20+ complex characters generated by a password manager. How does that rate?

Exceptionally well. Then again, I'm sure there's some selection bias in who responds. 😄

Random passphrases with caps and numbers and the words separated by special characters. I am amazed when even 5 and 6 word passphrases break sites for being too long in 2025, pathetic.

If I can't manage a 3 word passphrase because of length limits I go full random.

I switched to passphrases because I was making too many mistakes transcribing 30 and 40 character fully random passwords when my password manager wasn't available on that device.