How long should your passwords actually be?

How long should your passwords actually be?





Have you noticed how password requirements have gotten stricter lately? These days, many services now require special characters in your password, and some organizations have increased their minimum password length to 16 characters or more. Technology-dependent businesses even require their employees to change their password regularly, and it must be different each time. Of course, you can use a password generator to create a complex, hack-resistant password, but a complicated password can do more harm than good if you lose it and can’t remember it. So, how long should your important passwords actually be?

The ideal password length is between 14 and 16 characters. This coincides with the theory put forward by psychologist Nelson Cowan, who claimed that a human being’s working memory is limited to about four “chunks” at a time. This means that it’s easier to remember a 14 to 16 character password if it’s made up of three to five memorable chunks. And according to password management service Bitwarden, a 16-character password with a mix of character types would take a hacker centuries to crack by brute force. Many account creation services still only require a password with a minimum length of eight characters, but in the age of new hacking threats, creating longer passwords is simply safer.

How to create a memorable and truly secure password

Longer passwords are harder to crack, but also harder to remember. One of the best ways to get around this is to create a passsentence instead of a password. It could be a short sentence that you can easily remember, or a series of seemingly unrelated words separated by spaces, hyphens, or other punctuation marks. Think of a passphrase as a mnemonic that you can remember by associating it with the act of accessing your account.

Phrases are often more secure than words alone because they inherently deter dictionary attacks. A dictionary attack occurs when a hacker uses a program to brute force their way into an account by trying all sequences of commonly used words and characters, as well as common variations. This tactic won’t work on you if your passphrase is made up of several words that are not commonly used together.

But what happens when you have a dozen different passphrases, all longer than 16 characters, for a dozen different accounts? Well, this is where you can still benefit from using secure password managers that users swear by. But it’s important to take password managers with a grain of salt. One of the most common ways to hack passwords is to look over someone’s shoulder or snoop through their phone. Malicious individuals can find your password manager on your phone, but they won’t find the passwords locked securely in your mind.



Similar Posts