
How to Create a Strong Password: Examples, Rules & Tips (2026)
Many people still rely on easy-to-remember passwords that hackers can crack in seconds, despite having dozens of online accounts. This guide explains how to create a strong password using methods like the 8-4 rule and three random words, backed by the latest expert advice.
Average time to crack a 12-character random password: 226 years (Hive Systems 2025) ·
Most common password in 2025: 123456 ·
Percentage of people who reuse passwords: 65% (Google/Harris Poll) ·
Minimum characters recommended by CISA: 16 ·
Number of passwords the average person manages: more than 100
Quick snapshot
- Using at least 12 characters increases cracking time significantly (Hive Systems 2025) ((NCSC))
- The three-word password rule is endorsed by the NCSC (NCSC)
- Common passwords like ‘123456’ are cracked instantly (NordPass 2025)
- Whether the 8-4 rule alone is still sufficient in 2026
- Exact time to crack passwords varies by attacker hardware
- Cracking time for 8-character passwords dropped to under 1 hour in 2025 (Hive Systems)
- Move toward passkeys and passwordless authentication is accelerating (Google)
Four key recommendations from leading authorities, one pattern: each emphasizes length over complexity tricks.
| Authority | Recommended minimum length |
|---|---|
| CISA (U.S. cybersecurity agency) | 16 characters |
| Google (identity security team) | 12 characters |
| Time to crack 8-character password | Less than 1 hour (Hive Systems 2025) |
| Time to crack 12-character password | 226 years (Hive Systems 2025) |
What is an example of a strong password?
Examples using random characters
A strong password built from random characters mixes uppercase, lowercase, numbers, and symbols. The National Institute of Standards and Technology (NIST, U.S. cybersecurity standards body) gives this example: S&h9!mP2@qL4. That’s 12 characters with no dictionary words – the kind a password generator spits out.
Examples using the three-word rule
The UK’s National Cyber Security Centre (NCSC) promotes picking three random words and joining them: coffee-turtle-bright. This method creates a long, memorable passphrase. To strengthen it, add a special character or number: coffee-turtle-bright!.
Examples for Gmail
Google Support recommends at least 12 characters and suggests using a phrase you can remember, like MyDogLikesToRun4Miles!. That’s 24 characters, easy to recall, and mixes case, numbers, and a symbol.
The pattern: combining length with randomness or memorable phrases creates strong passwords.
What is the 8 4 rule for creating strong passwords?
Origin of the 8-4 rule
The 8-4 rule has been a common industry baseline: at least 8 characters including one uppercase, one lowercase, one number, and one symbol. But this minimum UpGuard (cybersecurity research firm) says is “typically 8 characters, but longer passwords are better.” The National Cybersecurity Alliance (nonprofit security advocacy) states passwords should be at least 16 characters.
How to apply the 8-4 rule
If you still want to use the 8-4 rule, extend it. Start with a base phrase like Chapman University (higher education IT security) suggests: “My favorite vacation was in Hawaii.” Shorten it to MfvwiH, then add complexity: MfvwH@2021. That meets the 8-4 rule but is still too short by modern standards.
Following only the 8-4 rule leaves you vulnerable because 8-character passwords can be cracked in under an hour (Hive Systems 2025). The 8-4 rule is a floor, not a ceiling.
The implication: The 8-4 rule is outdated as a sole strategy. Modern guidance pushes you to 12–16 characters, making the old “8 with symbols” approach insufficient.
What is the 3 word password rule?
How the three random words method works
The NCSC (UK government cybersecurity authority) champions three random words because they are easier to remember than a jumble of characters. The idea: pick three unrelated words like apple-bridge-monkey. Because they aren’t a common phrase, the passphrase is long and unpredictable.
Why three random words can be secure
Length matters more than complexity. A 15-character passphrase of three words has far more combinations than an 8-character random string. NIST confirms that a passphrase can help you create something long and memorable. The National Cybersecurity Alliance adds that strong passwords are random strings of letters, numbers, and symbols — but a passphrase of three words achieves that randomness naturally.
The implication: three-word passphrases offer a good balance of security and memorability when augmented with a symbol.
What are 10 common passwords to avoid?
Most common passwords globally
According to NordPass (password management company) 2025 list, the top 10 most common passwords are:
- 123456
- password
- 123456789
- qwerty
- 12345
- 12345678
- 111111
- 1234567
- sunshine
- qwerty123
Why these passwords are dangerous
These passwords all have short length, predictable patterns, or dictionary words. Hive Systems 2025 shows that any 8-character password can be cracked in less than an hour — these common ones take seconds. The National Cybersecurity Alliance advises avoiding recognizable words, names, keyboard patterns, or dates.
Even a long password fails if it’s built from common words. “iloveyou123456” is 15 characters but still guessed quickly because it follows a common pattern.
The pattern: short length + common patterns = instant compromise. Avoid any password on the top 100 lists.
How to create a strong password for Gmail?
Gmail-specific password requirements
Google Support requires at least 8 characters but recommends at least 12. For Gmail, use a unique password that you don’t reuse elsewhere. Google’s password manager can generate and store strong random passwords for you.
Using Google’s password manager
Google’s built-in password manager creates random 15-character passwords by default. You can also use a phrase like MyDogLikesToRun4Miles! – long, personal, but not guessable. The National Cybersecurity Alliance says each account should have its own password, so never reuse your Gmail password elsewhere.
The trade-off: A custom phrase is easy to remember; a generated password is more secure but requires a manager. Use the manager for Gmail if you can.
Step-by-step: How to create a strong password
- Start with length. Aim for at least 16 characters, as recommended by NIST and National Cybersecurity Alliance.
- Use a passphrase. Pick three random words (e.g., “sunset-bicycle-rose”) and join them with hyphens or spaces. NCSC endorses this method.
- Add complexity. Insert a number and a symbol, like “sunset-bicycle-rose!7”. Chapman University advises using numbers, symbols, and even spaces.
- Make it unique. Never reuse passwords across accounts. The National Cybersecurity Alliance says each account should have its own password.
- Use a password manager. NIST recommends managers to generate and store strong passwords. Google’s manager and others can handle the heavy lifting.
- Enable multifactor authentication. NIST says the first thing you should do is add multifactor authentication. Even a strong password benefits from a second layer.
Confirmed facts
- Using at least 12 characters dramatically increases cracking time (Hive Systems 2025)
- The three-word password rule is endorsed by the NCSC (NCSC)
- Common passwords like ‘123456’ are cracked instantly (NordPass 2025)
What’s unclear
- Whether the 8-4 rule alone is still sufficient in 2026
- Exact time to crack passwords varies by attacker hardware
The pattern: using a password manager and multifactor authentication provides comprehensive security.
“Use a random string of mixed-case letters, numbers and symbols. For example: ‘S&h9!mP2@qL4’.”
“Long passwords are stronger, so make your password at least 12 characters long.”
For the average person managing more than 100 passwords, the choice is clear: use a password manager to generate and store unique, long passwords for every account, and enable two-factor authentication wherever possible. The weakest link is no longer the password itself — it’s the human habit of reusing them. Those who rely on a manager and a passphrase for their most critical accounts (like Gmail) will stay ahead of attackers in 2026.
Frequently asked questions
What is a strong 8 character password example?
An example is G7k@zP1! — 8 characters with mixed case, a number, and a symbol. But 8-character passwords can be cracked in under an hour, so aim for 12+.
What is a 12 strong password example?
S&h9!mP2@qL4 is a 12-character random password from NIST. Another is coffee-turtle-bright from the three-word rule.
How does a password generator work?
A password generator creates a random string of characters using cryptographically secure algorithms. Most built-in managers (like Google’s) generate 15-character random passwords by default.
Should I use a password manager?
Yes. NIST and the National Cybersecurity Alliance both recommend password managers to generate and store unique passwords for each account.
How often should I change my password?
Current best practice from NIST says only change passwords if you suspect a compromise. Routine periodic changes are no longer recommended.
What is the most common 8 digit password?
12345678 is the most common 8-digit password, followed by 11111111. Both are cracked instantly.
Are password rules the same for all sites?
No. Some sites enforce 8-character minimums, others require symbols. Always use the maximum length the site allows. For Gmail, Google recommends at least 12 characters.
What this means: addressing common questions helps reinforce best practices.