Protect

7 Rules for an Unbreakable Password

Short passwords get guessed in human order. Length and no reuse beat adding one extra symbol.

What Does a Password Actually Protect?

A password acts like a key that proves "this is really you." If someone steals your key, they can read your emails, hijack your social media, sell your in-game items, and in the worst case expose your credit card details or family information. The critical difference from a physical house key is that an online password can be attacked by criminals from anywhere in the world — simultaneously. That is why you need something far stronger than a lock on your front door.

Strong vs. Weak: What Makes the Difference?

Password Length vs. Cracking Time (high-speed machine estimate) Source: Hive Systems Password Table 2024 (GPU brute-force basis) Length Digits only Lowercase only Upper+lower+digits +Symbols too 6 chars Instant Instant Instant 5 seconds 8 chars Instant 2 seconds 7 minutes 8 hours 10 chars 5 seconds 1 hour 1 month 5 years 12 chars 2 hours 3 weeks 200 years 30,000 years 14 chars 3 weeks 50 years 800,000 years 200M years Recommended: 12+ characters mixing all 4 types (uppercase, lowercase, digits, symbols) "8 chars + letters and digits" can be cracked in 7 minutes today. Length is your biggest defense. ▶ But dictionary words (password, taro123, etc.) are cracked instantly regardless of length.
Fig. 1: Password length vs. cracking time. 12+ characters mixing all 4 types buys centuries to hundreds of millions of years.

The two main cracking methods are "dictionary attacks" (trying common words and phrases rapidly) and "brute-force" (trying every possible combination). An 8-character lowercase-only password falls in seconds on a home PC; a 12-character password mixing uppercase, lowercase, digits, and symbols would take modern high-speed machines hundreds of years. Length directly equals strength.

The 7 Rules You Must Follow

Password Strength Self-Check (all 7 checked = strong) Think of your current password as you go through each item □ ① Length: Is it 12 or more characters? Shorter = weaker. Even adding just 2–4 characters to a short password significantly boosts protection. □ ② Mix: Does it include all 4 types — uppercase, lowercase, digits, and symbols? Example: "Tr#9mq2K!Lx". Three types is OK, but four is better. □ ③ No meaningful words in it? Your name, birthday, favorite idol, pet name, favorite song → dictionary attack cracks these instantly. □ ④ Different password for every site? (No reuse) One site leaks → all your other accounts fall. At minimum use unique passwords for email, SNS, and games. □ ⑤ Not shared on paper or through messaging apps? Don't share with family, friends, or partners. Even "temporary" sharing leaves a trail in chat history. □ ⑥ Managed with a password manager? Bitwarden (free), 1Password, iCloud Keychain — you only need to remember one master password. □ ⑦ Also using two-factor authentication (2FA)? Even if your password leaks, a second check can stop the attacker. (Covered in detail in No. 4.)
Fig. 2: 7-point password strength checklist. If any item fails, start with that one.

Let's go through each rule. ① Long is the most impactful — cracking time jumps dramatically past 12 characters. ② Mix means combining uppercase letters, lowercase letters, digits, and symbols. ③ No meaning means avoiding pet names, favorite idols, or anything guessable. ④ No reuse is especially important; one leaked service can cascade into all your other accounts. ⑤ Never write passwords on paper or share them through messaging apps. ⑥ is explained in the next section; ⑦ is covered in the next article.

The Solution: Password Managers

Hearing "use a random 12-character password that's different for every service" probably makes you think "there's no way I can remember all that." That's completely normal. That is exactly why security experts worldwide recommend managing passwords with a "password manager" app. Popular options include Bitwarden (free), 1Password, and Apple's built-in Keychain. You memorize only one master password; the app generates, stores, and fills in all the others. It syncs across your phone and computer.

The key is that your master password must be long and unique — never reused elsewhere. Rather than a short word, use a "passphrase": several unrelated words joined together with some digits and symbols mixed in. This balances strong security with memorability.

Password managers also double as anti-phishing tools. When you're on a real site the manager will suggest the saved password; on a fake site it won't, because the domain name is different. Password management and fake-site defense are actually connected.

Common Pitfalls

Frequent mistakes in password management
  • Using something simple like "password123." The most commonly used weak passwords are tried within the first few seconds of any attack.
  • Sharing with friends or partners. Cases of abuse after a breakup or argument are genuinely common.
  • Reusing the same password for school, social media, and games. One breach and everything goes down together.

How Does This Help Your Future?

Password management is not just a skill for IT professionals. As an employee you'll handle more and more accounts — internal systems, partner services, cloud tools. Whether you become "the person who leaked company data" comes down entirely to your personal security habits. Building the password-manager habit in your teens means you'll use it naturally in the workplace too.

Email, social media, games, cloud storage, and payment services are the top priorities. If your email is compromised, an attacker can reset passwords for all your other accounts too. If changing everything at once feels overwhelming, starting with email and your most-used social media account is already a big step.

What You Can Do Today

Today: stop one reuse
  1. Name two places that share a password
  2. Change one to a long passphrase with a parent
  3. Decide paper or a manager

Summary

The foundations of a strong password are: long, mixed, no meaningful words, no reuse. Not being able to memorize everything is normal — using a password manager is today's standard. Even one reused password means all linked accounts are at risk the moment it leaks. Start strengthening your most important accounts today.

Check Which is stronger?