CYBER WELFARE

Protect your Digital Privacy

Password Strength: Why Some Break in Seconds and Others Last Years

Additional resource for the lesson “Password Strength: Why Some Hold and Others Do Not” — Online Security course

Two passwords can look equally sensible and behave completely differently under attack. What separates them is not how complicated they appear, but how much genuine unpredictability they contain. This resource explains where password strength actually comes from.

A. Why this matters

Some passwords give way in under a second. Others would take longer than anyone would spend. The difference is measurable, and it comes down to two things: how long the password is, and how little it can be predicted.

Everything else — the exclamation mark at the end, the 3 in place of an e — adds far less than it feels like it does. Attackers have been seeing those substitutions for twenty years.

The key idea: the longer, more random and more different a password is for each account, the harder it becomes to crack. Length does the heavy lifting; uniqueness limits the damage when something else goes wrong.

B. Key concepts

Six ideas, each with what it means for your own accounts.

Strong password

One that is long — at least 16 characters — and hard to predict. Current standards put the emphasis firmly on those two properties rather than on forced character rules.

Why it matters to you: It reframes the goal. You are not trying to build something that looks difficult; you are trying to build something nobody could anticipate.

Password entropy

A measure of how unpredictable a password is, and therefore how well it resists systematic guessing. It rises with length and with the variety of characters used.

Why it matters to you: It is the reason a long string of ordinary words can beat a short string of symbols: more possibilities to work through, not more visual complexity.

Passphrase

A long credential made of several words, often with a number and a symbol added. High unpredictability, and still possible to remember.

Why it matters to you: This is the right shape for the few passwords you genuinely have to type from memory — starting with the one protecting your password manager.

Password manager

Software that generates, stores and fills in a long, complex password for every account.

Why it matters to you: It lets you use credentials far stronger than anything you would invent, without carrying any of them in your head.

Cracking time

How long systematic guessing would take. Many common passwords fall in well under a second; long random ones move into timescales that make the attempt pointless.

Why it matters to you: It turns an abstract worry into something you can reason about: the goal is simply to be past the point where trying is worth it.

Password reuse

Using the same credential across services, so a breach at one place compromises the others.

Why it matters to you: This is the habit that undoes good passwords. A strong password used in five places is a strong password with four extra ways in.

C. A practical example: the same account, two ways

The weak version

For email, a single ordinary word, all lower case, no numbers or symbols:

almondmilk

This does not need to be cracked. It is a dictionary word, so it appears in the lists tried first.

A better version

1Alm0ndM1lk2*

Longer, mixed, harder. But still built on a word someone could guess at, with substitutions attackers have seen countless times. An improvement, not a solution.

The version that holds

A password generated by a manager, connected to nothing:

p$3Kf8Qm1z!L9u2d

The manager stores it and fills it in. You never see it and never need to. The only thing you remember is the master password — one credential, strong and unique.

The time needed to guess it moves from seconds to a span long enough that the attempt stops making sense. And you did less work, not more.

D. Try it yourself: a password upgrade session

Twenty minutes. Start with accounts where a mistake costs you nothing — a forum, a newsletter, an app you barely use.

Step 1 — Pick three low-stakes accounts

  • Nothing critical yet. This is practice, and practice should be safe.

Step 2 — Name what is wrong with each password

  • Too short? A dictionary word? Built on personal details? Used somewhere else too?
  • Naming it matters more than it sounds: it is what stops you rebuilding the same weakness.

Step 3 — Replace them

  • At least 16 characters.
  • Generated, not invented.
  • No names, dates, teams or whole words.
  • Stored in a password manager.

Step 4 — Then answer honestly

  • How hard was it to create passwords without using anything personal?
  • How much easier did the manager make it than expected?
  • Which critical account — email, bank, main social — deserves the same treatment next?

Doing it three times on accounts that do not matter is what makes doing it on the account that does matter feel routine.

E. Videos, articles and further resources

Independent and institutional sources in English.

NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
The standard that made length the priority over forced complexity, updated in August 2025. This is the source most other advice is drawing on.
https://pages.nist.gov/800-63-4/sp800-63b.html

CISA — Use strong passwords
Plain-language guidance on password length and on using a password manager.
https://www.cisa.gov/secure-our-world/use-strong-passwords

NCSC (UK) — Three random words, or #thinkrandom
The clearest short explanation of why three random words beat conventional complexity advice.
https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0

NCSC (UK) — Password managers: how they help you secure passwords
A sober answer to the question most people ask first: is it safe to keep all my passwords in one place?
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers

EFF — Creating strong passwords
A clear method for building a passphrase you can actually remember, including the dice-based approach.
https://ssd.eff.org/module/creating-strong-passwords

NCSC (UK) — Using password managers and passkeys to stay secure online
How password managers and passkeys reduce password fatigue rather than adding to it.
https://www.ncsc.gov.uk/blog-post/trust-the-tech-using-password-managers-passkeys-to-help-you-stay-secure-online

Links checked in August 2026. A note on the password-strength checkers you will find online: they are useful for demonstrating the principle with invented examples, but never type a password you actually use into one.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson works on the Skills pillar at level FL2, and turns directly into behaviour.

Skills

  • Creating high-entropy passwords and passphrases: 16 characters or more, mixed, unpredictable.
  • Using a password manager to generate, store and fill credentials.
  • Looking at a password and recognising what makes it weak — then fixing that specific thing.

For professionals and organizations

  • Reviewing internal policies that still require frequent rotation, which current guidance no longer recommends.

Awareness

  • Understanding that memorable but simple credentials give way to both dictionary and brute force attacks.
  • Seeing the difference between a recycled password and a unique one as a difference in blast radius, not in quality.
  • Connecting password quality directly to the security of your digital identity.

For future instructors and ambassadors

  • Being able to show why substitutions like 3 for e add almost nothing, without dismissing the effort behind them.

Secure Behavior

  • Upgrading critical credentials over time, starting with email and banking.
  • Using the password manager as a habit rather than an occasional tool.
  • Not building new passwords from names, dates or anything else that belongs to you.

For organizations

  • Providing a password manager rather than expecting people to solve the problem alone.

G. Questions to sit with

  1. How many of your passwords today would pass a basic test — 16 characters or more, mixed, no common words?
  2. If one service you use were breached tomorrow, how many other accounts would be exposed through reuse?
  3. How much time are you willing to spend today to avoid several difficult days later?
  4. Which account deserves the strongest credential you have: primary email, bank, or digital identity?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database most relevant to password strength.

Credentials

  • R1 — Do not reuse the same password: it is what turns one breach into several.
  • R2 — Use a reliable password manager, protected by a strong and unique master password.
  • R3 — Make each password at least 16 characters, with numbers, upper and lower case letters and symbols.
  • R4 — Turn on multi-factor authentication even where the password is already strong.
  • MS1 — Generate passwords automatically rather than inventing them by hand.
  • MS2 — Use autofill: it reduces typing errors and the risk of entering credentials on a fraudulent site.

Around the credentials

  • R6 — Keep your device software up to date. An outdated device can expose credentials however strong they are.

A note on R3. The 16-character minimum is doing most of the work here: NIST’s 2025 revision put length ahead of forced complexity. Mixing character types is still worth doing, mainly because many services require it — but never by shortening the password to fit.

The minimum useful step

  1. Choose one critical account today.
  2. Bring it to the standard: 16 characters or more, generated, unique.
  3. Store it in a password manager and turn on the second factor.
  4. Then plan to upgrade the others gradually over the coming weeks.

One account at a time is the realistic pace, and it is enough. The alternative — deciding to fix everything at once — is usually how the whole thing gets postponed.

In short

  • Strength comes from length and unpredictability, not from looking complicated.
  • Substitutions like 3 for e are familiar to attackers and add very little.
  • A generated password is stronger than anything you would invent, and costs you no effort to keep.
  • Uniqueness decides how much a breach elsewhere can reach.

Related resources in this course

Where this connects:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program