CYBER WELFARE

Protect your Digital Privacy

What makes a password hard to guess: the technology behind the rule

The recommendation says “at least 16 characters”. It is a rule of thumb, and like all rules of thumb it works better once you understand where it comes from.

This post explains how password strength is actually measured: why length weighs more than complexity, what a system does when it receives your password, and why the coloured indicators in sign-up forms almost always say the wrong thing.

It is the technology side of the recommendation sixteen character passwords.

The unit of measure: how much unpredictability it holds

The strength of a password is not measured in characters, but in unpredictability: how many possibilities somebody who does not know it would have to consider.

The technical term is entropy, and the idea is intuitive. A password chosen at random from ten possibilities is weak. One chosen at random from a billion is strong. What counts is not how it looks, but how wide the set it was chosen from actually is.

From which the central point, which sounds like a paradox: xkcd and Tr0ub4dor&3 can look equally complex and be worlds apart in strength — because the second derives from a known word with predictable modifications, so the real set of possibilities is far smaller than it appears.

Why every extra character multiplies

The mechanism is multiplicative, not additive.

If a password uses only lower-case letters, each position has 26 possibilities. Two positions have 26 × 26. Three, 26 × 26 × 26. Every character added multiplies the total.

Adding capitals, numbers and symbols widens the set for each position — from 26 to around 95. That is a real improvement, but it acts on the base; length acts on the exponent.

CompositionPossibilities per characterEffect
Lower case only26Narrow base
Lower + upper case52Base doubled
+ numbers62Slightly wider base
+ symbols~95Widest practical base

The practical conclusion: going from 8 to 16 characters produces an incomparably greater improvement than adding a symbol to an 8-character password. That is precisely why the recommendation speaks of a minimum length and not of “at least one special character”.

The great misunderstanding: random to whom?

There is a hidden assumption in all of this: that the password was chosen at random from within that set.

Almost no password is. People choose words that mean something, add the current year, put the capital at the start and the symbol at the end. Anyone trying to guess knows this, and does not start from random combinations: they start from habits.

That is why a formally “complex” password can be weak:

PasswordLooks likeActually is
P@ssw0rd!9 characters with capitals, numbers, symbolsA very well-known word with the three most widespread substitutions
London2026!City + year + symbolTwo predictable elements and a very common pattern
Qwerty123!A mix of every character typeA keyboard sequence
lamp rope blueberry windFour lower-case words, no symbolsFour independent choices from a wide vocabulary

The last row is the surprising one: it is made of nothing but lower-case letters and spaces, and yet it is by far the strongest of the four. Because the unpredictability is not in the characters: it is in the number of independent choices.

Why passphrases work

The word method exploits exactly this.

If you pick four words genuinely at random from a wide vocabulary, each word is an independent choice among many thousands of possibilities. Four choices of that kind produce an enormous set — and the password stays memorable, because the mind works with concepts, not with characters.

Two conditions for it to work:

  1. The words must be unconnected. salt pepper oil vinegar are not four independent choices: they are one choice, the category “seasonings”.
  2. They must not form a meaningful sentence. Proverbs, lyrics and quotations exist in ready-made lists.

Adding distributed capitals, a number and a symbol widens the set further and satisfies the formal requirements many sites impose.

What happens to your password when you register it

A serious service does not keep your password. It keeps the result of a one-way transformation — a process easy to compute in one direction and not reversible in the other.

When you sign in, the system applies the same process to what you typed and compares the results. If they match, it is you. The original password was never stored.

Two further measures are added to this:

  • a unique random value for each user (the salt), which prevents reusing calculations already done on other accounts;
  • a deliberately slow function, designed to make each individual verification attempt expensive.

Why it concerns you. If a service is breached and did things properly, whoever obtains the store does not have the passwords: they have values they have to try to work back from, one attempt at a time. How far they get depends almost entirely on how long and unpredictable your password is.

And if the service did things badly — keeping passwords in the clear or with outdated methods — no choice of yours can make up for it. That is why length alone is not enough: uniqueness (R1) and a second factor (R4) are needed too.

Speed limits: why not all attacks are equal

The strength required depends on where the attempt takes place.

Against the live service. Attempts are limited: after a few errors, slowdowns, extra checks or temporary lockouts kick in. Even a mediocre password holds for a long time, simply because it cannot be tried quickly.

Against a stolen store. Here there are no limits: attempts happen without going through the service, and there can be a great many of them. This is the scenario a long password is for.

From which a useful rule: length matters above all for the scenario you cannot control — the breach of a service you signed up to. On daily sign-in the service already protects you; on a stolen store only your password does.

Why the coloured indicators mislead

The meters that appear in sign-up forms — the bar going from red to green — almost always assess the shape: is there a capital? a number? a symbol? the minimum length?

The result is systematically distorted:

  • P@ssw0rd1! gets classified as “strong” — it is among the most tried in the world;
  • lamp rope blueberry wind gets classified as “weak” — it is enormously stronger.

More advanced evaluation tools exist, which compare the password against lists of common combinations, dictionary words and known patterns. They are far more reliable, but they are not the ones you find in most sign-up forms.

What to use instead: the four questions in how to make a password long enough — length, common word, personal detail, repeated pattern.

What changes with passkeys

Passkeys remove the problem at the root: there is no password to assess, because there is no password. Access happens through a credential tied to the device, unlocked by fingerprint, face or PIN.

Where they are available, they make any discussion of length unnecessary. But the transition will be long: a great many services will still use passwords for years, and the sixteen-character rule remains fully valid in the meantime.

Why 16, and not 12 or 20

The threshold is not a magic number: it is a trade-off, and knowing its terms helps you apply it with judgement.

Below 12 characters a password comes within range of what is realistically attackable against a stolen store, especially if it was not chosen truly at random — and almost none are.

Between 12 and 16 the margin widens, but stays sensitive to the quality of the choice: twelve characters built on a common word are worth far less than twelve random ones.

Above 16, with unconnected words or random generation, the cost of an exhaustive attempt leaves the practical horizon. That is the point where the weak link stops being the password and becomes something else: reuse, phishing, the device.

Beyond 20–25 the gain exists but is marginal compared with the other risks: attention is better spent on the second factor and on uniqueness than on five more characters.

This is also why the recommendation sets a minimum and not an optimum: above the threshold, the limiting factor is no longer the password.

What happens as technology changes

A reasonable question: will the sixteen-character threshold hold?

Computing power grows, and with it the speed at which combinations can be tried. The thresholds considered safe have risen over time, and will keep rising.

Two practical considerations, however, put the worry in proportion:

  • derivation functions adapt. The parameters that make each attempt slow are increased as hardware improves: it is a race in which the defence can keep pace;
  • the direction of travel is different. The path under way is not towards ever longer passwords, but towards removing the password altogether — passkeys and device-bound authentication.

In the meantime, a passphrase of four or five unconnected words has a wide margin, and is the choice that requires the least maintenance over time.

What technology cannot do

  • It does not make up for a reused password. If it appears in a breach elsewhere, its length is irrelevant.
  • It does not protect a password handed over voluntarily. On a fake site, 40 characters are worth the same as 4.
  • It does not fix a service that stores credentials badly. That is outside your control — and the answer is uniqueness, not length.
  • It does not make the second factor unnecessary. A password obtained remains a password obtained.

How to choose, in practice

If you are an individual. A passphrase of four or five unconnected words for the few passwords you type; randomly generated passwords of 20+ characters for all the rest, through a vault.

If you are a professional. The same, with particular care over the main email and the vault password, and with a second factor on everything that communicates outward.

If you set rules for others. Set a high minimum length and drop rigid complexity requirements: they produce predictable passwords. And do not impose periodic change without a reason: it generates incremental variants.

A rule of thumb. If a password can be described in words — “my daughter’s name with the year and an exclamation mark” — it is too predictable. If describing it would mean listing it character by character, or naming four unrelated words, you are on the right track.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsJudging a password on real unpredictability rather than appearance
AwarenessUnderstanding why form-based strength indicators are misleading
Secure BehaviourUsing length as the main criterion, in every context

Reference level: FL4 — Skilled. This is the level at which a rule is not applied because it was given, but understood at its foundation and adapted with judgement.

Conclusion

The sixteen-character rule is not arbitrary: it follows from the fact that strength grows multiplicatively with length and only linearly with character variety.

And it follows from a second fact, less technical: the passwords people manage to remember are the ones built on meaning, not on symbols. Length is the only requirement that runs with human memory rather than against it.

What to do next. Take the password you consider your safest and try to describe it in words. If you can do it in one sentence, it is more predictable than you think.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.