Docuboxer
By Sergio Alonzo Piña··5 min read

Strong password: why length beats complexity

The arithmetic behind password strength, the real number of bits in a word passphrase and the rules that no longer make sense.

A strong password is long, unique to each account and absent from lists of known passwords. Generate and Analyze Passwords creates one of up to 64 characters from a cryptographic generator, or analyzes yours to show which patterns weaken it, all in your browser, so what you type isn't sent anywhere. The math below shows why length beats mixing symbols.

What the current guidance says

NIST's SP 800-63B-4 says that when a password is the only authentication factor it should have a minimum of 15 characters. It also says services must not impose composition rules, such as requiring a mix of character types, must not force periodic password changes unless there's evidence of compromise, and must check new passwords against a blocklist of commonly used or compromised ones. In plain terms: length and not being known matter, and "must include a symbol" rules mostly don't.

How many bits each option gives

The theoretical strength of a randomly generated password is its length times the base-2 logarithm of the character set size. With the generator's sets, which add up to 89 characters (uppercase, lowercase, digits and 27 symbols):

Random passwordApproximate bits
8 lowercase letters (26 possible characters)37.6
12 characters of letters and digits (62 possible)71.5
16 characters from all sets (89 possible)103.6

Every extra bit doubles an attacker's work. Going from 8 lowercase letters to 16 characters of any kind multiplies the effort astronomically. And adding one symbol to a short password helps far less than lengthening it.

These figures hold for randomly generated passwords. One you invent yourself, like London2026!, doesn't earn those bits, because people follow patterns that attackers try first.

What a word passphrase is really worth

The tool also builds passphrases of words joined by hyphens, from 3 to 8 words, 6 by default. Its word list has 337 Spanish words, so each word adds about 8.4 bits and a 6-word phrase lands near 50 bits, well below the 103.6 of a 16-character random password. Passphrases help when you must type something from memory, and it pays to lengthen them: 8 words gets you near 67 bits. For accounts stored in a password manager, a long random password is the better choice.

Using the tool, step by step

  1. Open Generate and Analyze Passwords and choose Generate.
  2. Set the length (8 to 64, default 16) and the sets: uppercase, lowercase, digits and symbols. There's an option to exclude ambiguous characters (l, 1, I, O, 0) if you'll read it aloud or type it by hand.
  3. Copy the password. The generator uses cryptographic random numbers and guarantees at least one character from each active set.
  4. To check one of your own, switch to Analyze and type it. You get a score, an estimated time to guess it, and warnings such as "this is one of the most frequently used passwords" or "dates are easy to guess".

The analysis relies on a dictionary that includes Spanish and common English patterns. It is an estimate: a high score doesn't guarantee a password hasn't leaked, which is why the separate breach check exists.

Mistakes that weaken a password

  • Reusing it across accounts, even a good one.
  • Basing it on personal data: your name, a pet, a birthday or a recent year.
  • Predictable substitutions such as @ for a; attackers try them.
  • A capital only at the start and a digit only at the end, the most common pattern of all.
  • Writing it down somewhere unprotected. A password manager exists for exactly this.

The tool flags several of these patterns when it analyzes, with advice such as adding uncommon words or avoiding keys that run in sequence.

Generator, analyzer or breach check?

They answer different questions. The generator makes a password nobody has seen. The analyzer estimates how easy yours is to guess from patterns. Password Check tells you whether one already showed up in a known data breach. If yours did, see your password was in a data breach, now what?. And for how sites should store passwords, read MD5 vs SHA-256.

Frequently asked questions

How long should a strong password be?

The longer the better, and 15 characters or more is a reasonable benchmark under current guidance. Length adds more security than sprinkling symbols into a short password.

Can a password with only letters be strong?

Yes, if it's long and random. The tool even notes that you can create strong passwords without symbols, digits or capitals, as long as the length makes up for it.

How much is a word passphrase worth?

It depends on the word list and the word count. This tool's list has 337 words, so 6 words come to about 50 bits, less than a 16-character random password.

Should I change my password regularly?

Current NIST guidance says not to require periodic changes, and to change a password only when there's evidence it has been compromised.

Is my password sent to a server when I analyze it?

No. Generating and analyzing happen in your browser. Still, avoid typing your real password into any site you don't trust, and use a lookup that never sends the full password for breach checks.

Which is better, the analyzer or the breach check?

They do different things. One estimates how easy a password is to guess from patterns. The other checks whether it has already appeared in a known breach.

Generate and test a password

Length 8 to 64, word passphrases and a strength analysis. Runs locally, free, no signup.

Open Passwords →

Related tools

You might also like: your password was in a data breach, now what? and you leaked an API key: the damage control playbook.