Newsdeskly Insider Update English
NewsDeskly.com Newsdeskly Insider Update
Blog Business Local Politics Tech World

How to Create a Strong Password: Examples, Rules & Tips (2026)

James Ethan Hayes Bennett • 2026-06-11 • Reviewed by Daniel Mercer

Many people still rely on easy-to-remember passwords that hackers can crack in seconds, despite having dozens of online accounts. This guide explains how to create a strong password using methods like the 8-4 rule and three random words, backed by the latest expert advice.

Average time to crack a 12-character random password: 226 years (Hive Systems 2025) ·
Most common password in 2025: 123456 ·
Percentage of people who reuse passwords: 65% (Google/Harris Poll) ·
Minimum characters recommended by CISA: 16 ·
Number of passwords the average person manages: more than 100

Quick snapshot

1Confirmed facts
  • Using at least 12 characters increases cracking time significantly (Hive Systems 2025) ((NCSC))
  • The three-word password rule is endorsed by the NCSC (NCSC)
  • Common passwords like ‘123456’ are cracked instantly (NordPass 2025)
2What’s unclear
  • Whether the 8-4 rule alone is still sufficient in 2026
  • Exact time to crack passwords varies by attacker hardware
3Timeline signal
  • Cracking time for 8-character passwords dropped to under 1 hour in 2025 (Hive Systems)
4What’s next
  • Move toward passkeys and passwordless authentication is accelerating (Google)

Four key recommendations from leading authorities, one pattern: each emphasizes length over complexity tricks.

Authority Recommended minimum length
CISA (U.S. cybersecurity agency) 16 characters
Google (identity security team) 12 characters
Time to crack 8-character password Less than 1 hour (Hive Systems 2025)
Time to crack 12-character password 226 years (Hive Systems 2025)

What is an example of a strong password?

Examples using random characters

A strong password built from random characters mixes uppercase, lowercase, numbers, and symbols. The National Institute of Standards and Technology (NIST, U.S. cybersecurity standards body) gives this example: S&h9!mP2@qL4. That’s 12 characters with no dictionary words – the kind a password generator spits out.

Examples using the three-word rule

The UK’s National Cyber Security Centre (NCSC) promotes picking three random words and joining them: coffee-turtle-bright. This method creates a long, memorable passphrase. To strengthen it, add a special character or number: coffee-turtle-bright!.

Examples for Gmail

Google Support recommends at least 12 characters and suggests using a phrase you can remember, like MyDogLikesToRun4Miles!. That’s 24 characters, easy to recall, and mixes case, numbers, and a symbol.

Bottom line: The strongest examples combine length (12+ characters) with randomness or a memorable passphrase. For Gmail, a phrase like “MyDogLikesToRun4Miles!” beats a short random string.

The pattern: combining length with randomness or memorable phrases creates strong passwords.

What is the 8 4 rule for creating strong passwords?

Origin of the 8-4 rule

The 8-4 rule has been a common industry baseline: at least 8 characters including one uppercase, one lowercase, one number, and one symbol. But this minimum UpGuard (cybersecurity research firm) says is “typically 8 characters, but longer passwords are better.” The National Cybersecurity Alliance (nonprofit security advocacy) states passwords should be at least 16 characters.

How to apply the 8-4 rule

If you still want to use the 8-4 rule, extend it. Start with a base phrase like Chapman University (higher education IT security) suggests: “My favorite vacation was in Hawaii.” Shorten it to MfvwiH, then add complexity: MfvwH@2021. That meets the 8-4 rule but is still too short by modern standards.

Why this matters

Following only the 8-4 rule leaves you vulnerable because 8-character passwords can be cracked in under an hour (Hive Systems 2025). The 8-4 rule is a floor, not a ceiling.

The implication: The 8-4 rule is outdated as a sole strategy. Modern guidance pushes you to 12–16 characters, making the old “8 with symbols” approach insufficient.

What is the 3 word password rule?

How the three random words method works

The NCSC (UK government cybersecurity authority) champions three random words because they are easier to remember than a jumble of characters. The idea: pick three unrelated words like apple-bridge-monkey. Because they aren’t a common phrase, the passphrase is long and unpredictable.

Why three random words can be secure

Length matters more than complexity. A 15-character passphrase of three words has far more combinations than an 8-character random string. NIST confirms that a passphrase can help you create something long and memorable. The National Cybersecurity Alliance adds that strong passwords are random strings of letters, numbers, and symbols — but a passphrase of three words achieves that randomness naturally.

Bottom line: The three-word rule is a practical way to create long, memorable passwords. Its weakness: if the words are too common or related, attackers can guess them. Always add a number or symbol.

The implication: three-word passphrases offer a good balance of security and memorability when augmented with a symbol.

What are 10 common passwords to avoid?

Most common passwords globally

According to NordPass (password management company) 2025 list, the top 10 most common passwords are:

  • 123456
  • password
  • 123456789
  • qwerty
  • 12345
  • 12345678
  • 111111
  • 1234567
  • sunshine
  • qwerty123

Why these passwords are dangerous

These passwords all have short length, predictable patterns, or dictionary words. Hive Systems 2025 shows that any 8-character password can be cracked in less than an hour — these common ones take seconds. The National Cybersecurity Alliance advises avoiding recognizable words, names, keyboard patterns, or dates.

The catch

Even a long password fails if it’s built from common words. “iloveyou123456” is 15 characters but still guessed quickly because it follows a common pattern.

The pattern: short length + common patterns = instant compromise. Avoid any password on the top 100 lists.

How to create a strong password for Gmail?

Gmail-specific password requirements

Google Support requires at least 8 characters but recommends at least 12. For Gmail, use a unique password that you don’t reuse elsewhere. Google’s password manager can generate and store strong random passwords for you.

Using Google’s password manager

Google’s built-in password manager creates random 15-character passwords by default. You can also use a phrase like MyDogLikesToRun4Miles! – long, personal, but not guessable. The National Cybersecurity Alliance says each account should have its own password, so never reuse your Gmail password elsewhere.

The trade-off: A custom phrase is easy to remember; a generated password is more secure but requires a manager. Use the manager for Gmail if you can.

Step-by-step: How to create a strong password

  1. Start with length. Aim for at least 16 characters, as recommended by NIST and National Cybersecurity Alliance.
  2. Use a passphrase. Pick three random words (e.g., “sunset-bicycle-rose”) and join them with hyphens or spaces. NCSC endorses this method.
  3. Add complexity. Insert a number and a symbol, like “sunset-bicycle-rose!7”. Chapman University advises using numbers, symbols, and even spaces.
  4. Make it unique. Never reuse passwords across accounts. The National Cybersecurity Alliance says each account should have its own password.
  5. Use a password manager. NIST recommends managers to generate and store strong passwords. Google’s manager and others can handle the heavy lifting.
  6. Enable multifactor authentication. NIST says the first thing you should do is add multifactor authentication. Even a strong password benefits from a second layer.

Confirmed facts

  • Using at least 12 characters dramatically increases cracking time (Hive Systems 2025)
  • The three-word password rule is endorsed by the NCSC (NCSC)
  • Common passwords like ‘123456’ are cracked instantly (NordPass 2025)

What’s unclear

  • Whether the 8-4 rule alone is still sufficient in 2026
  • Exact time to crack passwords varies by attacker hardware

The pattern: using a password manager and multifactor authentication provides comprehensive security.

“Use a random string of mixed-case letters, numbers and symbols. For example: ‘S&h9!mP2@qL4’.”

NIST (U.S. cybersecurity standards body)

“Long passwords are stronger, so make your password at least 12 characters long.”

Google Support (identity security team)

For the average person managing more than 100 passwords, the choice is clear: use a password manager to generate and store unique, long passwords for every account, and enable two-factor authentication wherever possible. The weakest link is no longer the password itself — it’s the human habit of reusing them. Those who rely on a manager and a passphrase for their most critical accounts (like Gmail) will stay ahead of attackers in 2026.

Frequently asked questions

What is a strong 8 character password example?

An example is G7k@zP1! — 8 characters with mixed case, a number, and a symbol. But 8-character passwords can be cracked in under an hour, so aim for 12+.

What is a 12 strong password example?

S&h9!mP2@qL4 is a 12-character random password from NIST. Another is coffee-turtle-bright from the three-word rule.

How does a password generator work?

A password generator creates a random string of characters using cryptographically secure algorithms. Most built-in managers (like Google’s) generate 15-character random passwords by default.

Should I use a password manager?

Yes. NIST and the National Cybersecurity Alliance both recommend password managers to generate and store unique passwords for each account.

How often should I change my password?

Current best practice from NIST says only change passwords if you suspect a compromise. Routine periodic changes are no longer recommended.

What is the most common 8 digit password?

12345678 is the most common 8-digit password, followed by 11111111. Both are cracked instantly.

Are password rules the same for all sites?

No. Some sites enforce 8-character minimums, others require symbols. Always use the maximum length the site allows. For Gmail, Google recommends at least 12 characters.

What this means: addressing common questions helps reinforce best practices.



James Ethan Hayes Bennett

About the author

James Ethan Hayes Bennett

Coverage is updated through the day with transparent source checks.