Most advice about password strength is a decade out of date, including some of what used to be on this page. The rules people still repeat — mix in a symbol, swap an “o” for a zero, change it every few months — were written for a world with slower hardware and fewer breaches.
Here’s what actually matters now: length, randomness, and never using the same password twice. Everything else is detail.
Why password strength still matters
Your data in mSecure is protected with AES-256 encryption, and it’s encrypted on your device before it syncs anywhere. That’s the same standard used to protect classified government information.
But encryption has a key, and for your vault, that key is your master password. A strong lock on a door whose key is under the mat isn’t protecting much. This is why password strength is worth understanding rather than guessing at.
What makes a password hard to crack
Attackers rarely sit there typing guesses. They run software that tries enormous numbers of candidates against a stolen database, and they try the likely ones first.
Length is the biggest factor. Every character you add multiplies the number of possibilities. This is why a long, boring password beats a short, clever one — and it isn’t close.
Randomness matters as much as length. A twenty-character password built from a song lyric is weaker than it looks, because attackers feed lyrics, book passages, and previously-breached passwords into their tools. Real randomness has no pattern to exploit.
Uniqueness decides the blast radius. A strong password reused across five accounts is one breach away from being a weak password on all five. Attackers take credentials leaked from one site and try them everywhere else.
A note on the crack-time tables you’ll see online, including the one that used to be on this page: treat them with suspicion. Figures published a few years ago assumed hardware managing millions of guesses per second, while modern rigs manage billions. Any specific number ages badly. The direction of the advice — longer, more random, never reused — doesn’t.
What doesn’t work
Letter substitution. Turning “mountain” into “mOunT@1n” feels like a transformation. To a cracking tool it’s barely one — those substitutions are built into standard rulesets precisely because so many people use them. The word underneath is still a dictionary word.
Personal details. Pet names, birthdays, street names, your team. All of it is guessable, and much of it is public.
Complexity requirements as a substitute for length. Being forced to include a capital, a number, and a symbol tends to produce Password1! — technically compliant, trivially guessed. This is why NIST’s current guidance has moved away from composition rules in favour of length and screening against known-breached passwords.
Changing passwords on a schedule. Rotating every ninety days pushes people toward small predictable edits — Spring2025! becomes Summer2025! — and the standards bodies now advise against it. Change a password when there’s a reason to: a breach, a reuse, a suspicion.
So what should you actually do?
For nearly every account: don’t invent a password at all. Let a generator produce something random and long, and let your password manager remember it. There’s nothing to think up and nothing to recall, so the strongest option becomes the easiest one. mSecure’s generator is built in — set the length and character types and it does the rest.
For your master password: use a passphrase. This is the one you have to remember, so it needs to be strong and memorable. Four or five unrelated words in a row does both — long enough to resist brute force, random enough to avoid dictionaries, and far easier to recall than a string of symbols. Don’t use a famous quote or a lyric, and don’t reuse it anywhere else.
Worth knowing: your master password is the key that decrypts your mSecure vault, and mSecure has zero knowledge of it. We can’t see it, and we can’t reset it for you. That’s deliberate — it’s what stops anyone at mSecure, or anyone who compromises mSecure, from reading your data. You can read how that works in mSecure’s security model.
If you ever forget your master password, contact support before you reset your account. There is sometimes a workaround, and it’s worth asking first — because resetting is final. It clears the data in your account permanently, and the only way back from that is a backup you saved beforehand.
Check what you already have
New passwords are the easy part. The ones already in your vault are where the risk lives.
mSecure’s Security Center reviews your stored passwords and flags the weak and duplicated ones, which gives you a list to work through in order of what matters.
Have I Been Pwned tells you whether a password has appeared in a known breach. If one has, it’s on attacker wordlists, and its length stops being relevant.
Start with your email account. Every password reset in your life arrives there, so it deserves your strongest password and a second factor before anything else.
The short version
Long beats complex. Random beats clever. Unique beats memorable. Let software generate and remember the passwords you don’t need to know, and save your effort for the one master passphrase that protects the rest.
Download mSecure to generate strong passwords, store them encrypted, and see which of your existing ones need attention. Or take a look at everything mSecure does first.
