PASSWORD · SECURITY

How do I choose a strong password?

Reading time: 4 min Updated May 22, 2026 4,218 people found this article helpful
TL;DR

At least 12 characters, with a mix of uppercase, lowercase, digits, and symbols. Never use the same password on multiple sites. Avoid personal information (date of birth, name, favorite team). Use a password manager so you don't have to memorize anything. Enable 2FA on top for real security.

The rules of a truly strong password

Ktkarena enforces minimum rules:

  • At least 8 characters.
  • At least 1 digit.
  • At least 1 uppercase letter.

But these rules are a minimum. For real security, aim higher:

1. At least 12 characters (ideally 16+).

Why: an 8-character password can be cracked by an attacker in a few hours with consumer-grade hardware. At 12 characters with variety, it becomes decades. At 16+, it's statistically impossible.

2. A mix of 4 character types: uppercase, lowercase, digits, symbols.

Why: each type adds exponential "possibilities". A password with only lowercase letters has far fewer possible combinations than a varied password.

3. No recognizable personal information.

Your date of birth, your birth year, your last name, your first name, your dog's name, your favorite team, your city, your phone number… all of that can be guessed by someone who knows you a little. Avoid it absolutely.

4. Different for every site.

Your Ktkarena password must never be the same as on Facebook, Gmail, your bank, or any other site. If one of those sites gets hacked (it happens all the time), your other accounts stay safe.

The worst passwords to avoid at all costs

Here's the list of the most cracked passwords in the world (avoid at all costs):

  • 123456, 12345678, 1234567890
  • password, motdepasse, Password1, Password123
  • azerty, qwerty, qwertyuiop
  • name + year (e.g., marie2024, jean1990)
  • 000000, 111111, 12341234
  • admin, user, login
  • iloveyou, jetaime
  • footballer, lakers, realmadrid (favorite teams)
  • Your first or last name + a simple digit

If your password looks like one of these: change it now. An attacker with a password dictionary cracks this kind of password in under a second.

The passphrase technique

An excellent technique: use a full sentence as your password. It's easy to memorize and hard to crack.

Example: "MyBlackCatLoves7LuxuryKibbles!"

  • 30 characters (excellent).
  • Uppercase, lowercase, digits, symbols.
  • No full dictionary word in plain form.
  • Easy to memorize (it's a sentence that means something to you).

Another example: "Yaoundé2024-Rain&Mango42"

  • 24 characters, varied, memorable, unique.

Rule. Pick something that means something to you but that is not a well-known quote (algorithms have dictionaries of quotes). And personalize it with random digits and symbols.

Why a password manager is a game changer

The real problem: strong, unique passwords for 30 different sites are impossible for a normal human to memorize.

Solution: a password manager. An app that remembers your passwords for you, behind a single master password (which you memorize).

The best managers:

  • Bitwarden: free, open-source, cross-platform. Our top recommendation.
  • 1Password: paid (~€3/month), excellent design, very popular.
  • Dashlane: paid, with advanced features.
  • The manager built into your browser (Chrome, Safari, Firefox): less powerful but already much better than memorizing everything.

How it works in practice:

  1. You install Bitwarden (for example).
  2. You create an ultra-strong master password (the only one you memorize). It's the only access to all your other passwords.
  3. For each site, Bitwarden generates a strong random password for you (for example: "X8#mP2$qL9!nKv5wT").
  4. You never have to memorize anything again: Bitwarden autofills.

Result: you can have a different, strong password for every site, effortlessly.

FAQ

Frequently asked questions

Bitwarden offers a recovery option via email + recovery key (print it and keep it somewhere safe). Without it, you lose access - so treat your master password with the same care as your house keys.

The best managers (Bitwarden, 1Password) use zero-knowledge encryption: even they can't see your passwords. The rare historical incidents involved less serious products.

No, they're complementary. The password is your first barrier, 2FA the second. Ideally both are solid.

STILL STUCK?

Was this article helpful?

Prefer to talk to someone? Contact our support →
Link copied