Skip to main content

Is a ‘safe’ password even possible? We ask an expert

have i been pwned owner uncovers 13 million plaintext passwords leaked from free webhost is a safe password even possible we
guteksk7/Shutterstock
In the modern world, there’s no escaping the need for a password. Whether you’re logging into your work computer, keeping up with friends on social media, or checking your bank balance online, you’ll need a password to gain entry. Every password is supposed to be long, complex, and unique.

In a relatively short number of years, we’ve allowed passwords to become the core of our computer authentication process — it is the only thing protecting your bank accounts, email, everything you do online — but do ordinary, non-techie folks really know how vital a good password is, or how to make one? More importantly, is it possible for an ordinary person to remember a truly safe password in this day and age?

Understanding the strength of a password

It’s easy to point out a ‘bad’ password — the often-released lists of clangers like ‘password123’ and the ever popular ‘111111’ have given just about every active Internet user a glance at the worst of the worst. It’s more difficult to define a ‘good’ password.

Password strength is typically illustrated by a small bar presented during various account creation processes: green means you’re safe and red means you’re on thin ice. Those colors are typically an illustration of the various password rules that individual sites and services enforce.

It’s easy to point out a ‘bad’ password, but it’s more difficult to define a ‘good’ password.

Things get more complicated when you think about what these individual rules mean. Consider an average password that’s six letters long, which permits only the 26 letters of the alphabet to be used and is not case sensitive. There’s a 1 in 26 chance that you might guess each of the six letters — that makes the chances of guessing the password 1 in 308,915,776, or 26^6.

Now, consider that numbers are also allowed. That adds another 10 possibilities for each character, so we’re looking at 36^6 — which results in a huge change to the overall probability of guessing the string, putting the odds at 1 in 2,176,782,336.

However, most modern websites and services would not only allow for case-sensitive passwords, but necessitate the use of at least one capital letter. Those 26 letters are effectively completely separate from the lower case alphabet, so there’s now a 1 in 62 chance that someone could guess an individual character, and a whopping 1 in 56,800,235,584 chance that they could happen upon the entire password.

Remember, these are the calculations for a six-character password. Adding just one more character to the string would bump the chances up to a thoroughly gargantuan 1 in 3,521,614,600,000.

Password Comic
Image used with permission by copyright holder

The sheer heft of these figures might be reassuring to anyone who worries about online identity theft. Unfortunately, it’s not at all accurate to say that there’s only a 1 in 3,521,614,600,000 chance that your password could be cracked by a hacker. The problem? There’s a human component to the password.

How humans ruin passwords

It’s all well and good to say that a six-character password might have 3,521,614,600,000 possible combinations, but that supposes that the person selecting the password makes full use of the building blocks at their disposal. This is almost never the case.

I spoke to Joseph Bonneau, a Technology Fellow at the Electronic Frontier Foundation and a bona fide password expert. He told Digital Trends that the typical password is ‘very easily crackable’ — and what’s more, regular folks don’t seem to be more cautious when they’re creating passwords for the things that really matter.

Passwords are here to stay, at least for the immediate future, but many of us aren’t safely using them.

“It appears people are not able to choose strong passwords even when it seems to be in their interest to do so,” said Bonneau. We have to create a password for almost everything these days, but we’re terrible at picking them.

So, will we retire passwords in favor of something a little more secure?

“Their demise has been predicted many, many times,” Joseph replies, noting that he sees passwords retaining their dominance for at least the next five years. “As I have written about, I predict we will continue to evolve slowly, with passwords playing a smaller role but not being phases out completely for a very long time.”

Passwords are here to stay, at least for the immediate future, but many of us aren’t safely using them. The problem is the disconnect between human thinking and machine thinking. While the statistics might illustrate a wide open field of possible passwords, the average person is likely to fall into certain patterns.

While prominent password advice once stipulated that special characters were among the best forms of defence, that guidance has now largely been reconsidered. “Humans are not very clever adding these special characters — they usually just add a 1 or ! at the end — so they don’t add very much security but are very irritating to users.”

I asked Joseph about the much-shared comic above, and he thought it was rather close to the mark: “I think the dictionary words in that comic are a good example that something can be only very slightly harder to remember, or not at all, and yet be virtually impossible for a computer to guess.”

Lorrie Faith Cranor: What's wrong with your pa$$w0rd?

Just as quickly as probabilities can shrink when more more specificity and extra characters are mandatory, the traps we fall into making passwords make our authenticators much easier for a machine to guess — and machines are certainly the biggest threat. “Human attackers are amateurs,” Joseph said. “Any serious attacker will be using a computer so there is no real difference.”

Going purely by the numbers, passwords should be a lot more secure than they are. It’s the human factor that makes them more easily cracked by wrongdoers — but there are certain steps that you can take to stay a little safer.

How to create a safer password

As the above comic suggests, there’s some advantage to using a longer password filled with dictionary words. You can figure out your own method for remembering it, and it’ll take a lot more processor power and time for a computer to crack it.

It’s the combination of several words that makes this type of password powerful — as demonstrated earlier, an extra character can make a huge difference in terms of the overall amount of possible combinations.

However, it bears repeating that a lone dictionary word is a huge no-no when it comes to passwords. Anyone looking to crack your code will likely be using a piece of software that reels off words in the hopes one will be the answer, taking advantage of the fact that many people stick to the dictionary for their chosen password.

“For the few really important passwords, like your webmail, try to use randomly-generated passwords,” Joseph advises. “They are surprisingly easy to memorize.” The key is to avoid patterns, so try and keep that in mind.

Because you enter our password every day, this is a strong advantage over a computer, which only tries to access it once. A random selection of letters and numbers might be completely unfamiliar at first — but you’ll know it like the back of your hand if you use it frequently enough.

The next time you’re faced with coming up with a new password, try and think about it from the perspective of someone trying to crack your code. Choosing your cat’s name over a random stream of characters might be convenient at the time, but it could prove rather inconvenient if you fall foul of a breach later on.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Lenovo sale: Get up to 67% off ThinkPad Laptops, from $600
Lenovo ThinkPad X1 Carbon Gen 12 front angled view showing display and keyboard.

Lenovo has a huge laptop sale going on right now with select ThinkPad laptops available from just $600. If you need a new system for your small business, working on the move, or other productivity-focused plans, these are the laptop deals for you. With over a dozen laptops in the sale, it’s a good idea to take a look at the sale for yourself, but we’re also here with some insight into the best deals.

What to shop for in the Lenovo laptop sale
Lenovo is one of the best laptop brands for reliability and business purposes. One great starting point is being able to buy the for $600. According to Lenovo, it normally costs $1,839 which seems a little unrealistic but in keeping with Lenovo’s overly enthusiastic estimated value system. However, whatever the discount, this is a good laptop for the price. It has a 12th-generation Intel Core i5-1235U processor, 16GB of memory, and 256GB of SSD storage. For the display, you get a 14-inch full HD screen with 45% NTSC and 300 nits of brightness. There’s also a 1080p full HD RGB/IR Hybrid webcam with a privacy shutter and dual microphones.

Read more
Ghost of Tsushima is already shaping up to be a monster PC port
Jin wearing the Sarugami armor with Iki island in the background.

Sony detailed the features that will be available in the Ghost of Tsushima PC port on Tuesday, setting the stage for when the game launches on May 16. Despite some rocky PC ports from PlayStation Studios and porting studio Nixxes in the past, Ghost of Tsushima already looks impressive.
Ghost of Tsushima DLSS, FSR, and XeSS
It's launching with all of the modern bells and whistles a PC gamer could want. That includes support for Nvidia's DLSS 3 and AMD's FSR 3, both of which support upscaling and frame generation. There's also support for Intel XeSS, as well as native anti-aliasing modes for FSR and DLSS. This runs the game at native resolution but uses the anti-aliasing of the upscalers for improved image quality -- read our explainer on Nvidia Deep Learning Anti-Aliasing for more on that.

There's a treasure trove of features here that means virtually every PC gamer will have access to performance-boosting tech. FSR 3 support at launch is particularly noteworthy. Adoption of AMD's frame generation tech has been slow, and although we've seen it in recent games, it usually isn't available at launch.

Read more
The 5 best laptops for architects in 2024
AutoCAD

Architecture applications tend to require a lot of hardware resources, so laptops that work for architecture tend to be more like workstations than anything else. Of course, that does mean that they come at a pretty steep price, which is why we've picked our favorite laptops that will give you the most bang for your buck. The laptops below should easily handle most architecture applications you throw at them, although if you don't quite find what you're looking for, you may want to check out our list of the best laptops for CAD and 3D modeling.
The Best Laptops for Architects in 2024

Buy the  if you want the best overall laptop for architects
Buy the  if you want the best MacBook for architects
Buy the  if you want the best thin and portable laptop for architects
Buy the  if you want the best large-screen laptop for architects
Buy the  if you want the best dual-screen laptop for architects

Read more