When an 8-year-old cracks your password in under an hour, it is time to rethink what you actually know about password security.
That is exactly what happened to me. A child who had never seen me log in to my old iPad mini just kept guessing. Every wrong guess added a waiting period before she could try again, so in a full hour she had maybe ten attempts. Not ten thousand. Ten. And she still got in. Which means the code I was using was not secure at all. It was guessable.
This is the real problem with most passwords people use today. It is not about length or complexity in isolation. It is about whether someone who knows a little about you could narrow it down to a handful of likely options.
Birthdays are the most obvious example. So is 1234, the year you were born, or the same digit repeated four times. Bank PINs have this exact weakness. The bank locks you out after three wrong tries, so no one is sitting there running through every combination. They do not need to. If they know your birth year or your anniversary, they already have a short list to work through.
I proved this to myself with two combination locks. No software, no special knowledge. Just patience and a systematic approach. A 4-digit code with no lockout falls to anyone patient enough to work through the possibilities.
So what actually makes a password secure?
I used to believe a secure password had to be long and had to mix letters and numbers. Both of those things are true, but they are not the whole picture. The key insight that changed how I think about this came from a page I stumbled across at https://www.grc.com/haystack.htm and I would encourage you to have a look at it yourself.
Here is what it clarified for me. An attacker is not playing Mastermind or Wordle. No guess gives them any useful information other than right or wrong. They have to guess the entire password correctly, not parts of it. This means the goal is to make every possible guess take as long as possible. The number of characters matters, but so does the range of characters being used.
One dictionary word is weak because dictionaries are finite and attackers use them. Four random words strung together are dramatically stronger because the search space explodes. Add symbols, mixed case and a number and you push the difficulty out to timeframes that make brute-force attacks impractical.
This is the pattern I use now. I have two symbols that always appear in the same positions. I use upper and lower case letters. I include a number that stays consistent. The letters themselves are derived from the URL of the site I am logging into, which gives each password a unique core without me having to memorise a different random string for every account.
The honest caveat with this approach is that if one password is ever compromised, the pattern could potentially expose the others. That is why I also use two-factor authentication, 2FA, wherever it is available. A good password does not stop a determined attacker forever. It stops them getting in easily within a timeframe that works for them. 2FA adds another layer that makes the whole attempt significantly harder.
Password security best practices are not really about memorising rules. They are about understanding what you are actually defending against. You are not defending against someone with unlimited time and unlimited attempts. You are defending against someone looking for the path of least resistance. Make that path difficult enough and they move on.
If you want to understand more about how this kind of thinking applies to building goals that are actually achievable and worth protecting, this is worth your time:
Achieving goals the right way
