What length actually buys you
A longer random password takes longer to guess. That is the whole idea. You do not need to memorize it. You copy it into a password manager and let the manager type it for you.
- Eight to eleven characters: only if a website will not accept more.
- Twelve to fifteen characters: acceptable for most ordinary accounts.
- Sixteen characters: the default on this page, and enough for email and banking.
If you want the research behind those numbers, read the password length guide. If you want words instead of random characters, use the memorable password generator.
Save it before you close the tab
A random sixteen-character password is not something you keep in your head. Store it in a password manager. NordPass is the one I recommend for someone who is not comfortable with computers.
Frequently asked questions
Does this password go to a server?
No. The browser creates it on your device with crypto.getRandomValues(). Closing the tab discards it unless you copied it first.
Why not eight characters?
Many old websites still cap passwords at eight. That is too short for email or a bank. Use eight only when the site forces it.
What if I need a Wi-Fi password?
Use the Wi-Fi password generator. It is built for router fields, which often have their own length rules.