Attackers don’t guess passwords one character at a time. They try lists: passwords from earlier breaches, dictionary words, names and dates, with the usual tricks applied (a capital first letter, a 1 or ! at the end, @ for a). A password is strong when it isn’t on any of those lists and can’t be built from them.
Length beats complexity
Each character you add multiplies the work. Tr0ub4dor&3 looks complex but follows patterns crackers know. Four random, unrelated words, such as harbor velvet orbit quill, are both easier to remember and far harder to guess, because the words were picked at random, not by a person.
The rules that matter
- Unique for every site. When one site is breached, attackers try the same email and password everywhere else. A unique password stops that cold.
- Random, not clever. People are predictable. Let a generator choose.
- Long: at least 16 random characters, or 5 random words.
Never remember them
A password manager makes a random, unique password for each site, and fills it for you. You remember one strong master password, and nothing else.
Your master password
It’s the one you have to remember, so make it a passphrase: five or six random words, picked by rolling dice or by a generator, not by you. Vautir’s generator makes these. Vautir also adds your Secret Key, so even a stolen vault can’t be attacked by guessing your master password alone.
Check what you have
Vautir’s Security view shows which of your passwords are weak, reused or in known breaches, and takes you to each site’s change page.
Last updated October 3, 2026