The Method I Actually Use to Build a Password Worth Trusting

Sep 01, 2026By Jay Kells
Jay Kells

The Method I Actually Use to Build a Password Worth Trusting

I spent years following the same password advice everyone gets, mix in a capital letter, throw in a number, add a symbol somewhere, and you're covered. I followed it religiously and still ended up with passwords that were technically complex and practically useless, because I couldn't remember them, so I wrote them down, reused them, or tweaked the same base password slightly for every account. What actually changed things wasn't finding a stricter rule to follow, it was realising the rule itself was outdated. Here's the method I actually use now, and why it looks nothing like the advice I grew up with.


Why Length Beats Complexity, Every Time


The old advice was built around how humans might guess a password, not how computers actually crack one. A computer trying to break into an account isn't sitting there guessing "Password1!" and variations on it, it's running through enormous numbers of combinations automatically, and what slows that process down more than anything else is simply length. A long password made of ordinary words takes dramatically longer to crack than a short one stuffed with symbols, even though the short one looks more "secure" at a glance. Once I understood that, I stopped trying to make my passwords look complicated and started just making them longer. Sixteen characters minimum is where I sit now for anything that matters, and honestly getting there is easier than squeezing in symbols ever was.


The Passphrase Method I Actually Use


My actual method is embarrassingly simple once you know it, I string together several unrelated words into one long passphrase rather than trying to construct something dense and cryptic. Something like four random, unconnected words gives you a password that's both far longer and far easier to actually remember than a shorter jumble of characters, because your brain holds onto words better than it holds onto arbitrary strings. The key word there is unrelated, the words can't form a phrase or sentence that makes obvious sense together, since that predictability is exactly what makes a passphrase weaker. I'll throw in a number or a bit of unusual capitalisation somewhere in the mix too, more out of habit than necessity, but the length and randomness of the words themselves is doing almost all the actual work.


What I Deliberately Leave Out


Just as important as what goes into a password is what I make sure never goes anywhere near one. Names of family members, pets, birthdays, the street I grew up on, anything that shows up in a social media bio or that someone could piece together after ten minutes of looking at my public profile, all of that is off limits completely. This matters more than people think, because a huge number of successful account break-ins don't come from brute-force guessing at all, they come from someone using publicly available personal details to guess or narrow down a password directly. I also avoid any keyboard pattern, anything like a run of adjacent keys, because those get caught by cracking tools just as fast as "password123" does. If a detail is something I'd happily share at a dinner party, it doesn't belong anywhere near a password.


Array of precisely cut car keys showing transponder components and detailed craftsmanship with selective focus lighting

Every Account Gets Its Own, No Exceptions


This is the rule I was worst at following for years, and it's the one that actually matters most. Reusing even a strong password across multiple accounts means that a single breach anywhere, and it doesn't even have to be your fault, turns into a breach everywhere that password was used. I only really started taking this seriously once I accepted that memorising a genuinely unique passphrase for every single account I own simply isn't realistic, which is what finally pushed me toward using a password manager rather than my own memory as the storage system. NordPass generates and stores a properly unique passphrase for every account automatically, which means the "every account gets its own" rule stops being a discipline problem and just becomes the default. I've written separately about what I actually look for when choosing a password manager, which covers how I picked the one I use now.


How I Check a Password Actually Holds Up


Once I've built a password I'm happy with, I don't just trust that it's strong and move on, I actually check it. Most password managers, including the one I use, will flag a password as weak, reused, or old the moment you create or update it, which catches mistakes before they ever become a real problem. I also periodically check whether any of my existing passwords have shown up in a known data breach, since a password can be perfectly strong and still become compromised if the service holding it gets breached, at which point strength stops mattering entirely and changing it becomes urgent. Treating password strength as something to check rather than something to assume has caught more than one password I thought was fine but genuinely wasn't.


None of this requires remembering complicated rules or forcing yourself to type out a string of symbols you'll immediately forget, four unrelated words strung together, nothing personal or guessable mixed in, a unique one for every single account, and an occasional check to make sure it's actually holding up. That's the whole method, and it's held up far better for me than anything I was doing under the old capital-letter-and-symbol advice. The NCSC actually recommends this exact three-random-words approach as official UK guidance now, which is reassuring if you're wondering whether "just use ordinary words" can really be the secure option. If you want help putting the rest of your account security in order once your passwords are sorted, my free Safety Toolkit covers what I'd recommend next.