How to create secure passwords without losing your mind trying to remember them

Secure passwords may seem like a basic topic. After all, everyone knows that ‘123456’ is a terrible choice. Or do they? A Comparitech analysis found that among more than 2 billion login credentials exposed in 2025, this was still the most common password. ‘Admin’, ‘password’ and simple number sequences also ranked near the top. It is worth reviewing your accounts and checking whether your login security is really in good shape. Here is how to protect your credentials without having to memorise dozens of complicated strings.

‘123456’ is still going strong

People have been talking about secure passwords for years, yet lists of the most popular combinations still look as though nobody has been listening. Comparitech analysed more than 2 billion login records exposed in 2025. The most common included ‘123456’, ‘admin’, ‘password’ and ‘qwerty’. ‘123456’ alone appeared around 7.6 million times, and nearly two thirds of all passwords analysed contained fewer than 12 characters.

What else makes a password weak?

‘123456’ is not the only example of a poor password. Combinations based on a first name, company name, date of birth or a common word followed by a number and an exclamation mark are also weak. ‘Sophie1!’ may satisfy a website form, but that does not make it secure. These patterns are well known and predictable, and criminals have simple ways to crack them.

Why is ‘CompanyName2026!’ not enough?

A registration form asks for an uppercase letter, a number and a special character. So you take a familiar word, add ‘123!’, see a green confirmation message and move on. Technically, you have met every requirement, but the password still follows a very simple pattern.

Why is that a problem? A cybercriminal does not sit at a screen entering guesses by hand. They use programs that automatically test common words, keyboard patterns, number sequences and typical variations. That is why ‘qwerty’, ‘password123’ or a name followed by an exclamation mark are never good combinations. They are among the first variants tested during an attack.

One data breach, plenty of problems

Predictability is not the only problem. Even a good password stops protecting you effectively if you use it on several websites. A breach at one service is enough for criminals to test the same login details against your email, social media, shopping accounts and other services. That is why it is essential to use a unique combination in every place.

What does a good password look like?

A good password should be long, random and used for only one account. CERT Polska recommends at least 14 characters. It should not contain names, dates or other information that can easily be found online and connected to the account owner.

That sounds simple in theory. In practice, it is difficult to remember dozens of long, random combinations without mixing them up between services. Writing them on a note beside your monitor or in an ordinary note on your phone does not solve the problem either. Anyone who gains access to your desk or unlocked device then gets the entire list, together with details of what each password is for. The file could also end up in a cloud backup or be forwarded accidentally.

Fortunately, you do not have to choose between weak passwords and memorising complicated combinations. A password manager can do that job for you.

A password manager instead of notes and recycled patterns

A password manager creates a random password when you open an account, stores it in encrypted form and automatically enters it on the correct website. This means every service can have different login details, even if you use dozens of them.

This is how tools such as Bitdefender SecurePass work. The tool generates unique combinations and synchronises them across supported devices. It works on Windows, macOS, Android and iOS. It also warns you when it detects a weak, reused or compromised password.

That is not all it can do. SecurePass is also useful when you need to give a family member or colleague access to an account. Instead of sending the password by email, text message or chat, you can share it directly through the manager.

You protect access to your saved passwords with one master password. It therefore needs to be strong and unique, while still being easy to remember.

How do you create a strong password you can remember?

Not every password has to be a random string of letters, numbers and special characters. When you need to remember it, for example to unlock your password manager, you can use the passphrase method recommended by CERT Polska. This involves combining four or five random words. The result is a long combination that is easier to remember than a complicated string of random characters.

Examples might be ‘DancingBananaDiscoveredTelevisionMine’ or ‘Armchair droplet paper Eel’. An unusual combination like this is easy to picture, which helps you remember the chosen words. You can separate them with spaces or join them together, starting each one with a capital letter. If a service requires a number or special character, add one to the passphrase.

The full passphrase should contain at least 14 characters, and preferably more. Choose words with no obvious connection, and avoid common sayings, quotations or song lyrics. Do not base the passphrase on the names of people close to you, dates of birth or other information that could be found on your social media profile, for example.

A combination prepared in this way works well as the master password for your password manager. Just remember not to use it for any other service. The application can generate and store the rest of your passwords.

A good password is not enough. Enable 2FA

A long, unique password can still be stolen through a fake login page or exposed in an attack on a service. That is why important accounts should have another layer of protection: two-factor authentication, or 2FA.

How does it work? After entering your password, you must confirm the login in another way. This might involve a code from an authentication app or a notification on a trusted phone. Even if someone learns your password, they cannot sign in to your account without access to the second factor.

Start by enabling 2FA for your email, banking and work accounts, wherever an account takeover could cause the most damage.

When you enable 2FA, the service usually displays recovery codes. Save them in a secure place. You will need them if you lose your phone or access to the authentication app.

Use a passkey whenever it is available

More and more services let you sign in with a passkey. Instead of entering a password, you confirm the login on your device using a fingerprint, facial recognition or PIN.

Passkeys are very convenient and provide a higher level of security than traditional methods. A passkey is tied to a specific website, so a fake login form should not be able to capture it in the way it can capture a traditional password. Not every service offers this option, but it is worth enabling wherever it is available.

A hardware security key for your most important accounts

You can add a hardware security key to especially important accounts, such as your main email inbox, hosting account or administration panel. It is a small device resembling a USB flash drive that confirms a login when connected to a computer or held near a phone. Knowing the username and password alone is then not enough to access the account.

You need to have the hardware key with you, as you will not be able to sign in without it. It is therefore a good idea to keep a second key in a safe place in case you lose the first one.

For most accounts, a password manager and 2FA are enough. A hardware key makes sense where losing access would be particularly costly or disruptive.

The most common mistakes

Even if you know how to create a strong password, it is easy to slip back into old habits when you are busy. Before you start organising your accounts, check whether you are making any of these common mistakes:

  • Using one password for several accounts – it is convenient until one service suffers a data breach. Criminals can then test the same combination against your other services.

  • Making small changes instead of using a unique password – adding another number, the year or a service name does not provide the same protection as a completely new, randomly generated password.

  • Saving passwords in ordinary notes – such as a ‘passwords.txt’ file, a shared document or a note beside your monitor. It can expose login details to people who should not know them. Store passwords in an encrypted manager instead.

  • Sending login details in messages – a password sent by email or text message remains in the conversation history. If you need to share login details, use the password manager feature designed for that purpose.

  • Delaying your response to a data breach – if a service reports that data has been exposed, change the password everywhere you reused it. Do not wait for suspicious activity.

Your plan for today: start with a few simple steps

You do not need to sort out a hundred accounts in one evening. Start with those where an account takeover could cause the most damage:

  1. Set up a password manager. Install the tool and protect it with a strong master password.

  2. Secure your email with a unique password, enable 2FA and check that your account recovery details are up to date.

  3. Change reused or compromised passwords. Prioritise banking and business accounts.

  4. Enable 2FA for more services. Banking and accounts used for work should be your priority.

  5. Protect your 2FA recovery codes. Do not keep them only on the device you use to sign in.

Frequently Asked Questions

Have a project in mind?

Message us

Let's talk about how we can help bring your ideas to life.

Zanek

Can't keep up with changes in AI world?

Let us do the heavy lifting. Every week we distill the most important AI developments into a focused 5-minute briefing - so you stay ahead without the noise.

Find out more
Weekly AIonline