Length beats complexity
Password strength is entropy: bits of real randomness. A 8-character password using all character classes carries ~52 bits at best — offline-crackable. Four random common words (the diceware pattern) carry ~51 bits and are memorable. The modern guidance (NIST 800-63B) follows directly: length over composition rules, no forced rotation, screen against breached lists. Complexity rules like "must contain a symbol" push users to Summer2024! → Winter2024! patterns that crackers model first.
What actually protects accounts
- Unique password per site — credential-stuffing (replaying one breach everywhere) only works on reuse. A password manager makes uniqueness free.
- Multi-factor authentication — an app-based TOTP or hardware key removes the password's single point of failure. SMS codes are the weakest tier (SIM-swap).
- Passkeys where offered — phishing-resistant by construction; there is no secret to type on the wrong site.
How services must store passwords
Not encrypted — slowly hashed: bcrypt or Argon2id with per-user salts, tuned so one guess takes tens of milliseconds. MD5/SHA-256 storage means a breach equals plaintext. If a service emails you your current password, they failed this test.
Testing strength honestly
A good meter measures entropy (length × randomness), not rule checkboxes. The caveat: never paste a real, in-use password into any web page — including meters. Test with a similar-shaped password instead, or use a local/offline tool. Entropy math is public: ~log2(charsetlength) for random strings, far less for dictionary+pattern passwords.
Key hygiene for developers
- API keys and DB passwords are passwords: long random (32+ bytes), one per environment, rotated on exposure, stored in a secrets manager — never in git (even Base64'd; scanners decode).
- Rate-limit and add progressive delays on login endpoints; lockout isn't the only tool.
Check the entropy model and get generation guidance in the Password Strength analyzer — it runs entirely in your browser.