How to Create Passwords You Can Actually Remember
Short answer
Use four or five unrelated words as a passphrase — correct-anchor-mustard-violin — because length raises the number of possible combinations far more than swapping an a for an @ does. Memorise two or three of these, for your device, your email and your password manager, and let the manager generate random passwords for everything else.
On this page
Most password advice gets the arithmetic backwards. The rules people were taught in the 2000s, with one capital, one number, one symbol and a quarterly change, produce passwords that are hard for humans and barely harder for software.
Two things actually matter: length and not being used anywhere else. Everything else is decoration, and the decoration is why nobody can remember their passwords.
Why length beats complexity
A password-guessing attack works through possibilities. The number of possibilities depends on how many choices exist at each position, multiplied together across the length.
Adding a symbol widens the choice at one position. Adding characters multiplies the whole total again, for every added character. That is why a long password made of ordinary words outruns a short one full of punctuation, and it is arithmetic rather than opinion.
The substitution habit makes this worse. Replacing a with @, e with 3,
s with $ are the first transformations every cracking tool applies, because
they have been standard practice for twenty years. P@ssw0rd! is not meaningfully
stronger than password. It is just unpleasant to type.
There is a second failure that matters more than either. A password appearing in a breach dump is tried against every other service you use, automatically and immediately. No amount of complexity helps there. Only uniqueness does.
The passphrase method
Pick four or five words with no relationship to each other and no relationship to you. Join them however you like.
anchor mustard violin pebble
anchor-mustard-violin-pebble
AnchorMustardViolinPebble
All three are strong. The spacing and capitalisation are for the site’s rules, not for security.
The words must be random. This is the part people get wrong. If you pick them yourself you will pick a phrase, a line from a song, or things related to each other and to you, and the number of real possibilities collapses, because the attacker’s guess list is not “all words” but “phrases humans construct”.
Get randomness from something that is not your brain:
- Open a book at four arbitrary pages and take the first noun on each.
- Use dice and a word list. The diceware method is exactly this, formalised.
- Let your password manager generate a passphrase. Most offer a word-based mode alongside the random-character one.
Then make it memorable by building an image. Four random words become rememberable the moment you picture something absurd involving all of them — an anchor coated in mustard, resting on a violin, beside a pebble. That mental picture is what makes this method work, and it survives for years.
You only need to remember three
This is the part that makes the whole thing manageable. You are not creating forty memorable passwords. You are creating three, and generating the rest.
| Password | Why it must be memorised |
|---|---|
| Your device login | Needed before anything else is available |
| Your password manager’s master password | Nothing can store it for you |
| Your main email | The recovery route for everything else |
Everything else should be random characters produced by a manager and never seen. The quality threshold for those is different: nobody has to remember them, so they should be long, random and unique with no pattern at all. Whether to use a manager or your browser’s store covers that choice.
Three passphrases is a realistic memory load. Forty is not, which is why people who try end up with one password and a number on the end.
When the rules will not let you
Plenty of sites still enforce the old regime of maximum sixteen characters, a required symbol and no spaces. Sometimes maximum twelve, which tells you something unflattering about how they store it.
Adapt rather than abandon the method:
- No spaces allowed: join with hyphens, full stops or nothing.
- A symbol required: put one between two words.
anchor-mustard!violin. - A number required: add two digits at a join, not on the end where every pattern-based guesser looks first.
- A short maximum length: use fewer, longer words and accept it is weaker. Then make absolutely certain that password is used nowhere else, because uniqueness is now carrying the whole defence.
- No passphrase possible at all: let the manager generate the maximum permitted random string and never type it.
A site with a twelve-character cap and no 2FA is telling you not to trust it with anything important. Treat the account accordingly.
Habits that quietly undo all of this
- A base password with site names attached.
anchor-mustard-amazonandanchor-mustard-netflixare one password, not two. One breach exposes the pattern and the rest are trivial. - Incrementing numbers on rotation.
...violin2becomes...violin3. This is the behaviour forced rotation produces, and it is why the practice fell out of favour. - Personal source material. Pet names, children’s birthdays, your street, your team. All of it is in public or semi-public places.
- Keyboard patterns.
qwerty,1qaz2wsxand their neighbours are in every guess list, and they feel random while being nothing of the sort. - Reusing the master password anywhere. It protects everything else, so it gets used for one thing only.
Change passwords for a reason, not a schedule
Rotation on a calendar has been formally discouraged for years, because it makes people choose worse passwords to cope.
Change a password when:
- The service has announced a breach, or your manager flags it as exposed.
- You typed it somewhere you should not have, including a page reached from an email link.
- You shared it with someone and no longer want them to have it.
- It is reused, which is a reason on its own.
The priority order for a bulk password change matters if you are doing several, because changing them in the wrong order can lock you out partway through.
Realistic expectations
Three passphrases take an evening to create and about a week of mild hesitation to become automatic. After that they sit in memory for years.
The honest limit is that none of this protects an account whose password you typed into a convincing fake login page, or an account on a service that stores passwords badly. Strong unique passwords defend against guessing and against reuse after a breach. For everything else the useful addition is a second factor, which is why two-factor authentication does more for your email account than any password change will.