Guide

How to create a strong password

What actually makes a password hard to crack, the UK’s official “three random words” advice, and how to stop trying to remember dozens of them.

Updated 25 Sept 2026 · 6 min read

Quick answer: a strong password is long, unpredictable, and used for one account only. The UK's National Cyber Security Centre (NCSC) recommends joining three random words — something like kettlepurplehorizon — that have no connection to you.

Then let a password manager or your browser remember your passwords, give your email account its own unique one, and turn on 2-step verification wherever you can.

Most password advice people remember — "use a capital, a number and a symbol", "change it every month" — turned out to make passwords harder to remember without making them much harder to crack. The advice below follows the NCSC, the part of GCHQ that publishes the UK's official guidance for the public.

What makes a password strong?

Criminals rarely guess passwords one at a time by hand. They use software that tries enormous lists of likely passwords: ones leaked in previous data breaches, dictionary words, names, dates, keyboard patterns, and all the usual tweaks people make to them. A password is strong if it isn't on those lists and can't be reached by working through them. That comes down to two things:

  • Length. Every extra character multiplies the number of possibilities. A long password made of simple parts beats a short one stuffed with symbols.
  • Unpredictability. Anything linked to you — your children's names, your football team, your birthday, your pet — is often findable on social media, and it's the first thing an attacker tries.

There's a third rule that matters even more: never reuse a password. When one website is breached, attackers try the leaked email and password combinations on other sites. If you've used the same password elsewhere, one breach unlocks every account that shares it.

The "three random words" method

The NCSC's headline advice is to create a password by stringing together three random words. It's long enough to resist guessing, and far easier to remember than Tr0ub4dor&3-style gibberish.

  1. Pick three words that are random to you. Look around the room, open a book at a random page, or use a generator. kettle, purple, horizon.
  2. Don't make them a phrase. Song lyrics, film quotes and well-known sayings are exactly what cracking software checks. "Random" means the words don't belong together.
  3. Join them up. kettlepurplehorizon. If a website insists on a capital, number or symbol, add them — Kettlepurplehorizon7! — but the NCSC is clear that you don't need to make a password complicated to make it strong.
  4. Skip the clever substitutions. Swapping o for 0 or a for @ doesn't fool anyone; the software tries those automatically.

Three random words are ideal for the few passwords you genuinely have to type from memory: your email, your computer or phone, and your password manager.

Common password myths

Old password advice vs current NCSC advice
MythWhat to do instead
A strong password must be a jumble of symbolsLength and randomness matter more. Three random words are strong enough for most accounts.
Swapping letters for numbers (P@ssw0rd) makes it secureAttackers' tools try every common substitution. Choose unpredictable words instead.
You should change your passwords every few monthsThe NCSC advises against forcing regular changes. Change a password when there's a reason — a breach, or a suspicion someone knows it.
Never write a password downWriting passwords down is fine if you keep them somewhere safe and away from your device. A password manager is better still.
One really strong password is enough for everythingUse a different password for every account, so one breach can't unlock the rest.

Let a password manager do the remembering

A unique password for every account is impossible to memorise, and the NCSC's answer is to stop trying. A password manager — a dedicated app, or the one built into Chrome, Edge, Safari or Firefox — creates strong passwords, stores them, and fills them in for you. The NCSC points out some useful side effects:

  • It only autofills on the genuine website, which helps protect you against phishing pages that look like the real thing.
  • It syncs across your devices, so a strong password is no harder to use on your phone than on your laptop.
  • Many warn you if a saved password has turned up in a known breach.

The NCSC says saving passwords in your browser is safe on your own devices, as long as you keep automatic updates switched on. Don't save them on a shared or public computer, like one in a library. Protect the password manager itself with three random words and 2-step verification.

Protect your email first

If you only fix one password today, make it your email. Almost every other account lets you reset its password by email, so whoever controls your inbox can take over the rest. Give it a strong password you use nowhere else.

Turn on 2-step verification, and use passkeys where you can

2-step verification (2SV) asks for a second thing, like a code from an app or a text, when you log in from somewhere new. Even if your password is stolen, the attacker is stuck without it. Switch it on for email, banking and social media first.

Passkeys go a step further: instead of a password, you sign in with your phone or computer's fingerprint, face or PIN, and there's nothing to guess, reuse or type into a fake site. The NCSC now recommends making passkeys your first choice wherever a service offers them.

Generating a password: random characters or a passphrase?

For passwords that live in a password manager, you never have to type or remember them, so let a generator create them. Altto's Password Generator offers both styles, using your browser's built-in cryptographic randomness, and runs entirely on your device:

  • Random characters pack the most strength into the fewest characters. With all four character types on, each character adds just over 6 bits of randomness, so the default 16 characters gives roughly 100 bits — far beyond what guessing can reach. This is the best choice for anything stored in a password manager.
  • Passphrases (like Tiger-Meadow-Amber-47) are easier to read out or type on a phone. Altto picks each word from a deliberately short, simple list of 256 words, so each word adds exactly 8 bits. That's less per word than words you'd choose from your whole vocabulary, so use more of them: seven or more words is where its strength meter shows Strong.

Whichever you use, the same rule holds: one password, one account.

Common questions

What is the NCSC three random words advice?
The UK's National Cyber Security Centre recommends making a password by joining three random words, such as kettlepurplehorizon. The words should have no connection to you and shouldn't form a well-known phrase. The result is long enough to be hard to crack but easy to remember.
How long should a strong password be?
There's no single magic number, but longer is better. Three random words usually come to 15 or more characters. For passwords you don't need to remember, because a password manager stores them, a random 16-character password or longer is a good default.
Do I need symbols and numbers in my password?
Not for strength. The NCSC says passwords don't need to be complex to be strong; length and unpredictability matter more. Add a number or symbol only if a website insists.
Is it safe to save passwords in my browser?
The NCSC says it is safe to save passwords in your browser on your own devices, provided you keep automatic updates switched on. Don't save passwords on shared or public computers.
Should I change my passwords regularly?
Not on a schedule. The NCSC advises against forcing regular password changes because it leads people to choose weaker, predictable passwords. Change a password if a service has been breached or you think someone else knows it.
Is a password generator safe to use?
A good one is. Altto's Password Generator creates passwords with your browser's built-in cryptographic randomness (the Web Crypto API) and runs entirely in your browser, so nothing you generate is sent to a server.

Need a password right now?

Generate a random password or passphrase with your browser’s own secure randomness — nothing you create is sent anywhere.

Generate a password