CYBER WELFARE

Protect your Digital Privacy

How to make a password long enough: the method, step by step

“Create a secure password” is an instruction that says nothing. Which characters? How long? How do you remember it?

This post answers with a concrete method, applicable in two minutes, and with the order in which it is worth sorting out the passwords you already have. It is the operational side of the recommendation sixteen character passwords.

Before you start: two categories of password

The distinction that simplifies everything else.

The passwords you have to type by hand. There are few of them: the vault’s master password, the computer login, the home Wi-Fi, perhaps a couple of accounts you open on different devices. These have to be long and memorable.

The passwords you never type. These are all the others, dozens of them. The vault fills them in. They have to be long and random, and you do not have to remember them.

Almost all the effort people associate with passwords comes from treating the second group like the first.

1. Prevention: the method for building them

For the passwords you have to remember: the word method

What to do. Pick four or five words with no logical connection between them. Not a sentence, not a proverb, not a lyric: words that do not normally sit together.

A practical way to find them: look around and take the first object you see in four different corners of the room. Or open a book at random four times and take the first word on each page.

Then add variety, spread out. Not all the capitals at the front and the symbols at the back: distribute them among the words.

StepExample
Four unconnected wordslamp rope blueberry wind
Add capitals, not just at the frontLamp rope Blueberry wind
Separate with different symbolsLamp-rope_Blueberry!wind
Insert a number, not at the endLamp-rope9_Blueberry!wind

Result: 25 characters, memorable through a mental image, with no personal reference at all.

What to avoid at this stage: words connected to each other (salt pepper oil vinegar), references to you (London Moon 1985 Arsenal), famous phrases, keyboard sequences.

For all the others: let the vault generate them

What to do. When you create or change a password on a service, use the vault’s generator: set 20 characters or more, with every character type enabled, and save.

Why it counts. A randomly generated password contains no patterns, derives from no dictionary word and cannot be traced back to you. And it costs nothing in memory: you will never see it.

If you do not use a vault yet, see recommendation R2.

When a site imposes tight limits

What to do. Some services accept only 12 or 16 characters, or forbid certain symbols. Use the maximum allowed, keep as much variety as possible, and compensate by turning on the second factor.

A low limit says something about the service, not about you: if it is an account holding something important, it is worth asking whether to keep it there.

Always add the second factor

What to do. On email, bank, cloud, work and on the vault itself. A long password plus a second factor is the combination that holds in almost every scenario — including the one where the password is obtained anyway.

2. Detection: telling whether a password is weak

Use the vault’s analysis

What to do. Almost every vault has a feature that lists short, duplicated or breach-exposed passwords. It is the fastest way to know where to start, without having to think about it.

Check whether your address appears in known breaches

What to do. Well-known services let you check whether an email address has appeared in public breaches. Enter only the email address, never the password.

What the result means. A positive result says that service was breached, not that your current account is compromised. It is still a good reason to change that password everywhere you had used it.

Apply the four-question test

What to do. For each important password:

  1. Is it under 16 characters?
  2. Does it contain a common word, even one dressed up with symbols?
  3. Does it contain something about me — a name, a date, a place, a team?
  4. Is it built to the same pattern as another of my passwords?

One yes is enough to rewrite it.

Be wary of “strength meters”

What to know. The coloured indicators appearing in sign-up forms almost always assess only the presence of capitals, numbers and symbols. They give “strong” to P@ssw0rd1! and “weak” to a thirty-letter lower-case passphrase. Do not use them as your criterion.

3. Response: when a password has to change immediately

You do not need a calendar. You need reasons.

Change a password when:

  • a service reports a breach affecting you;
  • the vault or the browser flags that it has appeared in a public list;
  • you notice a sign-in or activity you do not recognise;
  • you shared it with someone and it is no longer appropriate that they know it;
  • you typed it on a device you do not trust, or on a page that later turned out to be fake;
  • you realise it is weak according to the four questions above.

How to change it. Not by editing the old one: rewrite it from scratch. If the compromised password was Home2024!, the new one cannot be Home2025!.

The order. Always start from the main email: it is the recovery key to the other services. Then bank and payments, cloud, work, the rest.

4. Recovery: what to do if a password has already given way

  1. Change the main email password, from a device you trust.
  2. Sign out of active sessions, after changing the password.
  3. Check the recovery details: secondary email, phone, security questions.
  4. Review connected apps and revoke anything you do not recognise.
  5. Change the passwords on other accounts where you used that password or a variant of it.
  6. Warn your contacts if messages went out from your account, using a different channel.

A plan in two sessions

Session 1 — The passwords you type (20 minutes)

  1. Rewrite your vault’s master password using the word method.
  2. Do the same for your computer login and your home Wi-Fi.
  3. Check you remember them: type each one once without looking.

Session 2 — The passwords you do not type (20 minutes, repeatable)

  1. Run the vault’s analysis and sort the results by severity.
  2. Replace the critical accounts’ passwords with generated ones.
  3. Every time you sign in to a service over the following months, replace that one too.

The passwords that deserve special treatment

Not all of them play the same role. Five cases deserve a rule of their own.

The vault’s master password. It is the one every other password depends on. It should be the longest you can remember, typed by hand regularly so you do not forget it, and never used anywhere else in any form.

The main email password. It is the recovery key to every other service. Even if you keep it in the vault, it is worth having it memorable: if you lost access to the store, that is where you would start again.

The computer login. It gets typed several times a day, often in front of other people. It has to be long but quick to type: three short words work better than five long ones.

The home Wi-Fi. It has to be read out to guests, so it must be pronounceable. The word method is perfect: Vase-Trumpet-Cloud-42 can be dictated over the phone without spelling it out. Whoever gets onto a home network sees the traffic of the connected devices, so length counts here too.

Shared passwords. If a credential is used by several people, it should be handled in the vault with a shared folder, not passed on by voice or message. And it should be regenerated when someone leaves the group — not merely revoked.

How to check you have really remembered it

A step almost everyone skips, and the main cause of lost passwords.

After creating a password you have to remember:

  1. Type it three times in a row at the moment of creation, without looking.
  2. Try it again the next day, before it becomes essential.
  3. Type it in full once a week, even if you normally use fingerprint or face recognition.
  4. If after a week it does not come to you, change it: a password you cannot remember will end up written down, and at that point the problem moves elsewhere.

A practical aid: build a mental image linking the four words into an absurd scene. Lamp-rope9_Blueberry!wind becomes “a lamp hanging from a rope, with nine blueberries swinging in the wind”. Improbable scenes are remembered better than lists.

Frequent mistakes when creating passwords

  • Complicating instead of lengthening. X7#k does not help; four words do.
  • “Clever” substitutions. @ for a and 0 for o are known and tried first.
  • The meaningful phrase. A proverb or a lyric is predictable: you need unconnected words.
  • All symbols at the end. It makes the structure recognisable.
  • The hidden personal detail. Even modified, it remains the first attempt.
  • The long password used everywhere. Length does not replace uniqueness.
  • Changing out of habit. It produces predictable variants; better to change when there is a reason.
  • Trusting the coloured meter. It measures the shape, not the strength.

Operational checklist

Stage 1 — The passwords you remember

  • ☐ Vault master password built from unconnected words, over 16 characters
  • ☐ Computer login and home Wi-Fi updated with the same method
  • ☐ No personal detail in any of them

Stage 2 — The passwords you do not remember

  • ☐ Vault analysis run
  • ☐ Critical accounts’ passwords regenerated randomly
  • ☐ No duplicated password left on important accounts

Stage 3 — Reinforcement

  • ☐ Second factor enabled on email, bank, cloud, work and the vault
  • ☐ Checked whether my address appears in known breaches
  • ☐ Previously shared passwords replaced

A short scenario

Sarah discovers, from the vault’s analysis, that she has 31 passwords under 12 characters.

She does not change them all. She changes six: email, bank, two payment services, cloud, work account. It takes twenty minutes, because the vault generates them and she does not have to remember them.

Then she changes the vault’s master password to four unconnected words, and types it every morning for a week until it becomes automatic.

The remaining 25 she replaces over the following months, one at a time, whenever she signs in to that service. Without giving up a single evening to the problem.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsBuilding a long, memorable password with a repeatable method
AwarenessTelling apart the passwords to remember from the ones to generate
Secure BehaviourApplying the method to every new password, instead of improvising

Reference level: FL2 — Beginner, with elements of FL3 — Autonomous in the analysis and progressive replacement part.

Conclusion

Creating a strong password requires neither imagination nor an extraordinary memory. It requires stopping complicating one word and starting to put four together.

What to do right now. Build your vault’s master password with the word method — or your email password, if you do not use a vault yet. It is the password every other one depends on.

To see where you stand, the digital resilience self-assessment gives you a reference point.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.