At minimum 12 characters, but 16+ is recommended for 2026. With modern hardware, even 12-character passwords can be cracked in hours if they use common patterns.
Should I change my passwords regularly? +
Modern guidance says no — change passwords only when there's a breach or suspected compromise. Forced regular changes lead to weaker passwords (Password1!, Password2!, etc.).
Is a passphrase better than a random password? +
A passphrase like "correct-horse-battery-staple" is often better than a short random password because it's easier to remember while being very long. However, a 16+ character random password with all character types is still the gold standard.