How to create secure passwords
The number of online accounts that everyone in the meantime has in tow is steadily increasing. These include social media accounts, e-mail accounts, and countless access to online shops. Many, however, always use one and the same password for the various accesses, which makes it easy for hackers – once the password has been breached – to make some nonsense with their access data in no time at all.
According to Statista data, only very few Germans use a sufficient number of different passwords.
This may be due to the fact that many are not aware of the importance of password security, and on the other hand, of course, because it seems almost impossible to remember so many different passwords that should ideally be as complex as possible.
How to create secure passwords
The number of online accounts that everyone in the meantime has in tow is steadily increasing. These include social media accounts, e-mail accounts, and countless access to online shops. Many, however, always use one and the same password for the various accesses, which makes it easy for hackers – once the password has been breached – to make some nonsense with their access data in no time at all.
According to Statista data, only very few Germans use a sufficient number of different passwords.
This may be due to the fact that many are not aware of the importance of password security, and on the other hand, of course, because it seems almost impossible to remember so many different passwords that should ideally be as complex as possible.
The length of the password is important
When assigning a password, you are often asked to use at least one uppercase letter and a special character like % or /. However, what is not sufficiently checked is that the password is long enough. Although there is a minimum number of characters required, this is often too short, according to the National Institute of Standards and Technology (NIST).
Because a password should be at least 8 characters. And this is really only the absolute minimum! Better are 12 or 16 characters. It would also be desirable to allow the providers spaces in passwords, which would increase the possibilities of complexity, and thus the security again.
A short password with, for example, only 8 characters, even if you spam them with special characters, can be detected in a relatively short time by computers that do nothing but try out passwords. And already the culprits have gotten a hit again to drive Schindluder with your data. If the same password applies to other accounts then the damage can be considerable.
For if you buy at your expense on the Internet, and the goods are delivered to any packing stations you may not notice this at first, or very late. Then it will be difficult if not impossible to find the perpetrators who often sit abroad, while you stay at high cost. Because it was not hacked the portal where your access data were tapped, but you yourself were the victim of a hacker attack, which you have apparently made possible by insufficient security arrangements.
The length of the password is important
When assigning a password, you are often asked to use at least one uppercase letter and a special character like % or /. However, what is not sufficiently checked is that the password is long enough. Although there is a minimum number of characters required, this is often too short, according to the National Institute of Standards and Technology (NIST).
Because a password should be at least 8 characters. And this is really only the absolute minimum! Better are 12 or 16 characters. It would also be desirable to allow the providers spaces in passwords, which would increase the possibilities of complexity, and thus the security again.
A short password with, for example, only 8 characters, even if you spam them with special characters, can be detected in a relatively short time by computers that do nothing but try out passwords. And already the culprits have gotten a hit again to drive Schindluder with your data. If the same password applies to other accounts then the damage can be considerable.
For if you buy at your expense on the Internet, and the goods are delivered to any packing stations you may not notice this at first, or very late. Then it will be difficult if not impossible to find the perpetrators who often sit abroad, while you stay at high cost. Because it was not hacked the portal where your access data were tapped, but you yourself were the victim of a hacker attack, which you have apparently made possible by insufficient security arrangements.
How do I remember long passwords?
As we said before, with strong passwords, the creativity and convenience of many users are failing to come up with a sensible password. Many then resort to password generators, which are however not particularly recommendable, because here the passwords created at some point are the same, and can easily be spied out.
Another option is to use a password manager for all your passwords. Here then a single master password is sufficient to get to all other data. But the BSI has come to the conclusion that this alternative is risky. Because if only a single password is needed to then get sorted by a variety of passwords with the associated portals that may not be the right solution.
Your passwords should be as individual as possible, and preferably consist of a whole sentence, in which you then exchange certain letters for numbers (for example, an E against a 3, or a B against an 8, etc.). The sentence should also be really individual and not something like “youcannot getinhere”.
It is best to form sentences that have emerged from personal life events that really only you and maybe a handful of people from your personal environment can know, and convert them by exchanging letters for numbers and / or special characters, and uppercase and lowercase letters ,
So take the time to invest in your online security, because the damage caused by inadequate security measures can bring you much more trouble.
How do I remember long passwords?
As we said before, with strong passwords, the creativity and convenience of many users are failing to come up with a sensible password. Many then resort to password generators, which are however not particularly recommendable, because here the passwords created at some point are the same, and can easily be spied out.
Another option is to use a password manager for all your passwords. Here then a single master password is sufficient to get to all other data. But the BSI has come to the conclusion that this alternative is risky. Because if only a single password is needed to then get sorted by a variety of passwords with the associated portals that may not be the right solution.
Your passwords should be as individual as possible, and preferably consist of a whole sentence, in which you then exchange certain letters for numbers (for example, an E against a 3, or a B against an 8, etc.). The sentence should also be really individual and not something like “youcannot getinhere”.
It is best to form sentences that have emerged from personal life events that really only you and maybe a handful of people from your personal environment can know, and convert them by exchanging letters for numbers and / or special characters, and uppercase and lowercase letters ,
So take the time to invest in your online security, because the damage caused by inadequate security measures can bring you much more trouble.
Popular Posts:
Microsoft Loop in Teams: The revolution of your notes?
What exactly are these Loop components in Microsoft Teams? We'll show you how these "living mini-documents" can accelerate your teamwork. From dynamic agendas to shared, real-time checklists – discover practical use cases for your everyday work.
Career booster 2026: These Microsoft Office skills will take you further!
A new year, new career opportunities! But which Office skills will really be in demand in 2026? "Skilled use" is no longer enough. We'll show you today's must-haves – like advanced Excel, using AI in the office, and relevant certifications for your resume.
Why Zero Trust doesn’t work without identity protection!
Zero Trust means: Trust no one, verify everyone. Identity protection is at the heart of this modern security model. Learn how IAM, MFA, Conditional Access, and the principle of least privilege effectively protect your business when the old network perimeter is gone.
How AI fuels cyberattacks – and how it protects us from them
Cybercriminals are using AI for deepfakes and automated attacks. Defenses are also relying on AI: through behavioral analysis (UEBA) and automated responses (SOAR). Learn how this arms race works and how modern security strategies can protect your business.
Information overload: Protection & tips against digital stress
Constantly online, overwhelmed by news, emails & social media? Digital information overload leads to stress and concentration problems. Learn the best strategies and practical tips to effectively protect yourself, manage the chaos, and regain your focus.
Put an end to password chaos: Why a password manager is important
Passwords are constantly being stolen through data leaks. A password manager is your digital vault. It creates and stores strong, unique passwords for every service. This effectively protects you against identity theft through "credential stuffing".
Popular Posts:
Microsoft Loop in Teams: The revolution of your notes?
What exactly are these Loop components in Microsoft Teams? We'll show you how these "living mini-documents" can accelerate your teamwork. From dynamic agendas to shared, real-time checklists – discover practical use cases for your everyday work.
Career booster 2026: These Microsoft Office skills will take you further!
A new year, new career opportunities! But which Office skills will really be in demand in 2026? "Skilled use" is no longer enough. We'll show you today's must-haves – like advanced Excel, using AI in the office, and relevant certifications for your resume.
Why Zero Trust doesn’t work without identity protection!
Zero Trust means: Trust no one, verify everyone. Identity protection is at the heart of this modern security model. Learn how IAM, MFA, Conditional Access, and the principle of least privilege effectively protect your business when the old network perimeter is gone.
How AI fuels cyberattacks – and how it protects us from them
Cybercriminals are using AI for deepfakes and automated attacks. Defenses are also relying on AI: through behavioral analysis (UEBA) and automated responses (SOAR). Learn how this arms race works and how modern security strategies can protect your business.
Information overload: Protection & tips against digital stress
Constantly online, overwhelmed by news, emails & social media? Digital information overload leads to stress and concentration problems. Learn the best strategies and practical tips to effectively protect yourself, manage the chaos, and regain your focus.
Put an end to password chaos: Why a password manager is important
Passwords are constantly being stolen through data leaks. A password manager is your digital vault. It creates and stores strong, unique passwords for every service. This effectively protects you against identity theft through "credential stuffing".


























