CYBER WELFARE

Protect your Digital Privacy

Sixteen character passwords: why length beats everything else

For years we were taught that a safe password is a complicated one: a short word, a number standing in for a letter, a symbol at the end, a capital at the start. P@ssw0rd! looked like the model.

It never really was, and today it is even less so. That kind of password is hard for a person to remember and easy for a program to try — the worst possible combination.

Recommendation R3 moves the attention to where it counts: length. At least 16 characters, mixing upper and lower case, numbers and symbols. And, as you will see, the simplest way to get there is not to complicate one word: it is to put several together.

What this recommendation says

Recommendation R3 states that every password should be at least 16 characters long and should combine upper and lower case letters, numbers and special characters.

The two requirements do not carry the same weight, and it is worth knowing that:

  • length is what makes a password hard to arrive at through automated attempts: every extra character multiplies the number of possible combinations;
  • character variety widens the set of symbols to be tried, and makes the password less traceable to a dictionary word.

What it is not. It is not a request to memorise sixteen random characters. A sixteen-character password can be made of four ordinary words — and in that case it is easier to remember than Xk7#mQ2, as well as far stronger.

Nor is it a rule about periodic changes. Changing a password every three months out of habit leads people to build predictable variants (Summer24!, Autumn24!). A long, unique password should be changed when there is a reason: a suspicion, an exposure alert, a sharing arrangement that no longer applies.

Where it applies. To every password, with priority given to the accounts that would do the most damage if compromised.

Why length beats complexity

The reasoning is simple, and worth going through once.

A program trying combinations works through every possibility of a given length. Adding one character does not add a little difficulty: it multiplies it by the number of possible symbols.

The practical result:

PasswordLengthWhy
P@ssw0rd!9Short, built on a very well-known word with predictable substitutions
Tr0ub4dor&311Hard to remember, still within reach of automated attempts
horse-battery-paperclip-lantern31Four ordinary words, no connection between them: out of reach

Substitutions like a→@, o→0, i→1 have been known for decades and are tried first. They add no protection: they add difficulty only for the person who has to remember them.

There is a second reason, less technical and equally important: a password you can remember does not get written down. Passwords that are too complicated end up on a sticky note, in a phone note, in a message sent to oneself — and from there the problem changes nature entirely.

A concrete example

Helen needs a new password for her email account.

First attempt: Helen2026!. Ten characters, a first name, the current year, an exclamation mark. It looks like it follows the rules — capital, numbers, symbol — but it contains public information and one of the most common patterns there is.

Second attempt: GreenTable-Floor7-Cactus!. Twenty-four characters, three elements with no relationship to each other, capitals, a number, two symbols. Helen remembers it because she built a mental image; nobody can derive it from her personal details.

The difference is not imagination: it is that the second one derives from nothing guessable.

When to apply it

  • When you create a new account. That is the moment it costs nothing.
  • On your main email account, before anything else. It is the recovery key to every other service.
  • On your vault’s master password. It is the only one you have to remember: it must be long and memorable.
  • When a service warns you that your password has appeared in a breach.
  • When a site imposes a low limit (say 12 characters): use the maximum allowed, and turn on multi-factor authentication to compensate.
  • On shared networks and devices: the Wi-Fi password, the hotspot, the router.

How to apply it

  1. Start from the word method. Pick four or five words with no logical link between them. Not a meaningful sentence, not a proverb, not a song lyric: unconnected words.
  2. Add capitals, numbers and symbols in a non-obvious way. Not all at the beginning or the end: spread them between the words. Cloud7-Bicycle_Copper!Forest is a good model.
  3. Check you are above 16 characters. Four average-length words get there on their own.
  4. Do not use personal information. Names of family members and pets, dates, places, teams: these are often derivable from public profiles.
  5. Let the vault do it, where you can. For every account you do not have to type by hand, the best choice is a long, randomly generated password: you do not have to remember it. See recommendation R2.
  6. Keep the word method for what you type. The vault’s master password, the computer login, the home Wi-Fi: those you do have to remember, and that is where a passphrase is the right answer.
  7. Add the second factor. A long password plus multi-factor authentication is the combination that covers almost every scenario.

Widely held beliefs worth revisiting

Advice about building passwords circulates that was correct for years and no longer is. That is nobody’s fault: the knowledge changed.

“You need at least one special character.”

It helps, but marginally. Adding a symbol to an eight-character password produces a far smaller improvement than taking it to sixteen. Rigid complexity requirements have a documented side effect: they push people towards predictable patterns — capital at the front, symbol at the back.

“You should change it every three months.”

Forced periodic change produces incremental variants (March24!, June24!), which are more predictable than the password you started with. The most recent international guidance has dropped this advice: you change when there is a reason, not when a deadline expires.

“Spaces aren’t allowed.”

Many services accept them. Where they are not possible, hyphens or dots do the job with nothing lost.

“A long password is impossible to remember.”

True for a random sequence of characters, false for four words. Lamp-rope9_Blueberry!wind has twenty-five characters and is remembered through a mental image; Xk7#mQ2p has eight and has to be written down.

“If the site accepts 8 characters, 8 is enough.”

The site’s limit concerns the site, not the risk. A service that accepts short passwords is a service worth keeping anything important away from — and one to enable a second factor on regardless.

“Browser-saved passwords are fine.”

They are better than nothing and much better than reuse. The limits show up when you step outside your ecosystem, or when you want an analysis of what you actually have.

Common mistakes to avoid

  • Predictable substitutions. @ for a, 0 for o, 1 for i: these are tried first.
  • The common word made longer. passwordpassword is long, but it is one very well-known term repeated.
  • The famous phrase. Song lyrics, quotations, titles: they are already in ready-made lists.
  • Using the keyboard as a guide. qwertyuiop, 1qaz2wsx: known sequences, tried early.
  • The changing final number. Home2024! → Home2025! is not a new password.
  • Personal details. Even when they feel private, they are often derivable.
  • The same long password everywhere. Length does not replace uniqueness: the two rules apply together (R1).
  • Forced periodic change. It produces predictable variants. Better a long, unique password, changed when there is a reason.

How this connects to the Cyber Welfare Framework

PillarHow this contributes
SkillsBuilding a long, memorable password without falling into known patterns
AwarenessUnderstanding why length weighs more than apparent complexity
Secure BehaviourApplying the method to every new password, instead of improvising

Digital maturity levels.

  • FL1 — Basic. Short passwords, often built on common words or personal details.
  • FL2 — Beginner. Critical accounts have long passwords, with no personal references.
  • FL3 — Autonomous. Every password exceeds 16 characters; those not typed by hand are randomly generated.
  • FL4 — Skilled. You can judge a password’s strength and recognise weak patterns, including in other people’s.
  • FL5 — Expert-Guide. You teach the word method and correct the widespread beliefs about complexity and periodic change.

R3 accompanies the step from FL1 to FL2 and remains a requirement at every level above.

How to check you are applying it properly

  1. Does my most important password exceed 16 characters?
  2. Does it contain anything derivable from my public profiles?
  3. Is it built from a single word, lengthened or modified?

Quick checklist

  • ☐ My main email has a password of at least 16 characters
  • ☐ My vault’s master password is a long, memorable passphrase
  • ☐ None of my passwords contains names, dates or places connected to me
  • ☐ I do not treat substitutions like @ for a as a protection
  • ☐ The passwords I never type are randomly generated
  • ☐ Where a site imposes a low limit, I have turned on a second factor

For an overall measure of where you stand, you can take the digital resilience self-assessment.

In short

The sixteen-character rule does not ask you to be more inventive: it asks you to be longer.

Four unrelated words, with a few capitals, a number and a symbol distributed among them, clear sixteen characters effortlessly and are remembered better than any sequence of symbols. For everything else — the accounts you never type by hand — the best answer is to let the vault generate the password.

Something to think about. Take the password you use most often: if you had to explain to someone how you built it, how hard would it be for that person to guess another one of yours?

Explore this recommendation

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.