VSThiran

How many characters should a password be?

Quick answer

At least 16 characters for ordinary accounts, per current guidance from CISA and similar bodies - longer is better, and modern NIST guidance allows passwords up to 64 characters. Length matters more than symbol variety for resisting brute-force attacks.

Free, no sign-up, and your file is read on your own device rather than uploaded.

Password guidance has shifted in recent years: length now matters more than a specific mix of character types. A 20-character passphrase can be both easier to remember and harder to crack than a 10-character jumble of symbols, because each additional character multiplies the number of attempts a brute-force attack needs, while additional symbol complexity in a short password only adds so much.

Sixteen characters is a reasonable minimum for everyday accounts today; anything you can make longer without real inconvenience is worth doing, especially for high-value accounts like email and password managers.

Step by step

  1. Choose a length

    16 characters minimum for most accounts, 20+ for anything high-value like email or a password manager master password.

    Password Generator
  2. Generate it

    A random password using the full range of character types, generated with a cryptographically secure random source.

    Password Generator

Tips

  • A password manager removes the need to remember long random passwords at all - you only need to remember one master password, which is exactly where the extra length matters most.
  • Current guidance has moved away from mandatory periodic password changes - change one when there is an actual reason to (a breach, a shared device), not on an arbitrary schedule.

Common problems

A site rejects a long, randomly generated password.

Some older systems cap password length or reject certain symbols - if this happens, generate again with a shorter length or without special characters rather than abandoning a strong password entirely.

Frequently asked questions

Is a longer password really safer than a complex short one?
Generally yes - length has a larger multiplying effect on how long a brute-force attack takes than adding symbol variety to a short password does.
What is the maximum useful password length?
Current NIST guidance permits up to 64 characters. Beyond a certain point (well past 16-20 characters) the practical security benefit levels off, though a longer passphrase is never worse.
Does this password generator store what it creates?
No - generation uses your browser's cryptographically secure random source, and nothing generated is transmitted or stored anywhere.

Related related tools

Related articles

Ready to do it?

Free, no sign-up, and nothing is uploaded to a server.