Use Passphrases, Not Passwords.

13-1920-2930-5960+

Heads Up

The strongest passwords aren’t always the most complicated, they’re often the longest.

At a Glance

Many websites require passwords to contain capital letters, numbers, and special characters. While those requirements help, password length is often the biggest factor in creating a strong password. A long passphrase is usually easier to remember and harder to crack than a short password.

The Threat

Data breaches happen every year, exposing millions of usernames and passwords. Attackers collect these leaked credentials and use automated tools to try them against other websites.

This is why weak passwords and password reuse remain such a problem. If one account is compromised, attackers may gain access to several others that use the same password.

Outsmart It

Creating a strong password doesn’t have to be complicated.

Security experts recommend using passphrases instead of traditional passwords. A passphrase combines multiple words into something that is both memorable and difficult to guess.

Let’s use Batman as an example.

A password like:

  • Batman1!

may meet password requirements, but it is short and predictable.

A stronger option is:

  • TheDarkKnight1!

This passphrase is longer and much harder to crack while still being easy to remember.

To make it even stronger, exchange letters for numbers or special characters:

  • Th3D@rkKn1ghtR1s3s

The biggest improvement comes from making the password longer. The numbers and special characters add an extra layer of protection.

When creating your own passphrases:

  • Make them at least 12-16 characters long.
  • Avoid personal information such as birthdays or addresses.
  • Use a different password for important accounts.
  • Replace letters with numbers or symbols. (1 or ! = L or I, @ = A, 3 = E, $ = S, 0 = O)

The goal isn’t to create the most complicated password possible. The goal is to create a password that is both strong and memorable.

EXTRA CONTENT

Have Your Credentials Been Leaked?

Even strong passwords can’t protect you if a company storing them suffers a data breach.

Visit https://haveibeenpwned.com and enter your email address. The site will tell you if your email has appeared in a known data breach, including which company was affected and when the breach occurred.

If your email appears in a breach:

  • Change the affected password immediately.
  • Do not reuse that password anywhere else.
  • Enable multi-factor authentication (MFA) if available.

Checking only takes a few seconds and can help identify accounts that may be at risk.