Skip to main content
    Safety · Practice Sandbox
    New

    Password Practice

    Practice making and remembering strong passwords — in a safe sandbox. Your real passwords never go here.

    Step 1. Pick a memorable base phrase

    Think of a short sentence only you would say — a line from a song, a story about your dog, a favorite meal from a trip. Example: My beagle Sam ate 3 tacos in 2019!

    StrengthType a password to see its strength
    Length
    0 characters
    Time to crack (offline GPU guess)

    Step 2. Shorten to a code

    Take the first letter of every word. Keep any numbers and symbols as-is. Add something personal that only you know — a number of steps your dog takes, the year you got married, a favorite emoji-like symbol.

    Your short code will appear here

    Step 3. Make a per-site variation

    Never reuse the same password on two sites. A small tweak per site — the first three letters of the site name — means one leak won't expose every account. A password manager does this automatically with random values; this is the manual fallback.

    Per-site variation will appear here

    Red flags

    • Under 12 characters total
    • Uses a dictionary word with no changes
    • Includes your name, birthday, or pet's name alone
    • Has been used somewhere else already
    • Is on any "top 100 common passwords" list

    Green flags

    • 16 or more characters
    • Mix of UPPER and lower letters, numbers, symbols
    • A passphrase of 4+ unrelated words
    • A small per-site tweak so it's unique
    • Stored in a manager, not sticky-noted to a monitor

    Passphrase generator

    Tap the button for a random multi-word passphrase. Long and memorable beats short and cryptic every time. Practice only — don't reuse a phrase you generate here for a real account.

    Is it on a common-passwords list?

    Type a practice password to see if it matches our 100-entry sample of the most-reused passwords. Real managers like Bitwarden integrate with "Have I Been Pwned," which checks your password against hundreds of millions of real leaks without ever sending it over the internet.

    Two-factor authentication (2FA) — a second lock

    Even a perfect password can leak. 2FA asks for something else — a code, a tap, a physical key — so a stolen password alone is not enough to log in.

    Authenticator apps
    Google Authenticator, Microsoft Authenticator, Authy. Shows a 6-digit code that changes every 30 seconds. Strong, free, and the recommended default.
    Text message (SMS)
    A code sent to your phone. Better than nothing, but weaker — attackers can SIM-swap your number. Avoid SMS-only 2FA on your most sensitive accounts.
    Hardware keys
    A small USB/NFC key like YubiKey. Tap or insert it to approve a login. The gold standard — nearly impossible to phish. Worth it for email, finance, and work accounts.

    What to do if you get a breach email

    1. Don't click links in the email. The email itself could be a phish pretending to be a breach notice.
    2. Go to the real site directly. Type the web address or use your bookmark.
    3. Log in and change your password. Make the new one unique — don't reuse it anywhere else.
    4. Turn on 2FA while you're there, if it's not on already.
    5. Check every site that used the old password. This is another reason to lean on a manager — it tracks which sites shared which password.

    Sticky-note reality check

    Writing passwords down is fine — a password manager is better, but a notebook beats reusing "sunshine123" on every site. If you do write them down:

    • Keep the notebook in a locked drawer at home — never at work, never in a bag.
    • Use hints, not the full password. "Dog year + favorite song + !" is enough to jog your memory without being useful to a burglar.
    • Treat the notebook like cash. If it goes missing, change everything in it, right away.
    • Never label it "Passwords" on the cover.

    Frequently asked

    Is it safe to type here?

    Yes, for practice values you make up or that are generated on this page. Nothing is sent to a server, and nothing is stored other than your streak counter. Still — don't type your real, active passwords into any website that isn't the actual login page.

    Should I use a password manager?

    For almost everyone, yes. Even a free one like Bitwarden or Apple Passwords is a major upgrade over writing passwords in a notebook or reusing the same one. The one master password you still have to remember — that's the one worth drilling here.

    What's a passphrase?

    Several unrelated words strung together, sometimes with a number or symbol. Example:Lantern-Copper-Otter-Glacier-17!Longer than most "complex" short passwords, and far easier to remember.

    What about passkeys?

    Passkeys are a newer replacement for passwords entirely. Your device proves who you are with a fingerprint or face, and there's no password to steal or phish. More and more sites support them — turn them on when the option appears. They work alongside your existing password, not instead of it.

    Can I print my passwords?

    A printed emergency sheet kept in a safe or locked drawer is a reasonable backup — especially for your master password and recovery codes. Shred old copies. Never leave it in a car, laptop bag, or desk at work.

    Password Practice — Build, Type, Remember — TekSure