Skip to main content

2026-02-23

6 min

By Formatho Editorial

Password Security: How Strong is Your Password Really?

SecurityPasswordsAuthentication
Code configuration files on developer screen

Length beats complexity

Password strength is entropy: bits of real randomness. A 8-character password using all character classes carries ~52 bits at best — offline-crackable. Four random common words (the diceware pattern) carry ~51 bits and are memorable. The modern guidance (NIST 800-63B) follows directly: length over composition rules, no forced rotation, screen against breached lists. Complexity rules like "must contain a symbol" push users to Summer2024! → Winter2024! patterns that crackers model first.

What actually protects accounts

  • Unique password per site — credential-stuffing (replaying one breach everywhere) only works on reuse. A password manager makes uniqueness free.
  • Multi-factor authentication — an app-based TOTP or hardware key removes the password's single point of failure. SMS codes are the weakest tier (SIM-swap).
  • Passkeys where offered — phishing-resistant by construction; there is no secret to type on the wrong site.

How services must store passwords

Not encrypted — slowly hashed: bcrypt or Argon2id with per-user salts, tuned so one guess takes tens of milliseconds. MD5/SHA-256 storage means a breach equals plaintext. If a service emails you your current password, they failed this test.

Testing strength honestly

A good meter measures entropy (length × randomness), not rule checkboxes. The caveat: never paste a real, in-use password into any web page — including meters. Test with a similar-shaped password instead, or use a local/offline tool. Entropy math is public: ~log2(charsetlength) for random strings, far less for dictionary+pattern passwords.

Key hygiene for developers

  • API keys and DB passwords are passwords: long random (32+ bytes), one per environment, rotated on exposure, stored in a secrets manager — never in git (even Base64'd; scanners decode).
  • Rate-limit and add progressive delays on login endpoints; lockout isn't the only tool.

Check the entropy model and get generation guidance in the Password Strength analyzer — it runs entirely in your browser.

Formatho Editorial — written and maintained by the team behind formatho.com, a library of free, privacy-first developer tools that run entirely in your browser. Every guide is tested against the tools it describes. Corrections and suggestions: github.com/formatho.