How Long Should a Password Be in 2026?
Short passwords are cracked in hours. In 2026, length matters more than complexity tricks. Here’s how long you actually need — and how to generate it privately without sending anything to a server.
Length → bits → crack time
Strength is measured in bits of entropy: E = L × log₂(R) where L = length, R = pool size (94 for upper+lower+numbers+symbols, ~7776 for diceware words).
| Length | Pool | Bits | Strength in 2026 |
|---|---|---|---|
| 8 chars | 94 | ~52 | Weak — seconds to hours |
| 12 chars | 94 | ~79 | Okay for low-risk |
| 16 chars | 94 | ~105 | Strong |
| 20 chars | 94 | ~131 | Very strong |
| 4 words | 7776 | ~52 | Okay — needs 5–6 words |
| 6 words | 7776 | ~78 | Strong, memorable |
Crack times assume offline GPU/ASIC brute force with current hardware + Moore’s law. Online rate-limits help, but assume offline.
What NIST says in 2026
- SP 800-63B-4 (2025): No more forced rotation or complexity rules. Require at least 8 chars for user-chosen, at least 15 for generated; allow up to 64+. Screen against known-breached passwords.
- Our take: Don’t pick 8 because it’s allowed. Generate 16 random for sites, 5–6 words for master.
What to use when
| Use case | Recommendation (2026) |
|---|---|
| Master password, email, laptop | 5–6 word passphrase (canyon-pluto-mango-river-slate) — you type it |
| Every site/app, Wi-Fi, API key | 16–20 char random (9f$K2p@Lq8&Z1!xY4&) — copy from manager |
| Temporary/low risk | 12 chars minimum |
| Must include words for memory | 5 words, separator -, optional Capitalize |
Generate the right length — private, no upload
Open Password Generator →Slider 4–64 chars / 2–10 words • See bits live • Copy, history, works offline
How to generate it (20s)
- Open Password Generator.
- For random: Standard Password → set 16 (or 20) → keep upper/lower + numbers + symbols → Generate.
- For passphrase: Memorable Passphrase → 5–6 words → separator - → Generate.
- Look for 80+ bits (green bar). 16 chars ≈ 105 bits; 6 words ≈ 77–80 bits.
FAQ
Is 12 characters enough in 2026?
For low-risk logins, 12 (≈79 bits) is the floor. For email, banking, or master, use 16 (≈105 bits) or 6 words. Attacker power grows each year.
Are longer passwords always better?
Yes — length beats adding symbols. One extra random word (+12.9 bits) beats adding ! (+~2 bits).
Are generated passwords stored?
No. As on the tool page, generation uses your device’s CSPRNG. History stays in your browser session, works offline, nothing is sent.
Part of the Random Tools cluster. Also see Password vs Passphrase.