How Long Should a Password Be?
Password length is the single most important factor in resisting modern cracking attacks. Short passwords fail quickly after breaches, regardless of complexity.
Why Length Dominates Security
Each additional character exponentially increases the number of guesses an attacker must test.
Minimum Length Recommendations
- 12 characters: absolute minimum
- 16+ characters: strong baseline
- 20+ characters: high-risk environments
Online vs Offline Attacks
Offline attacks after breaches remove rate limits and lockouts entirely, making short passwords unsafe.
Passphrases and Memorability
Length only helps when users can remember passwords without unsafe workarounds.