Know-how / Password Security

How do I create secure passwords?

Create, check, and manage strong passwords.

A very reliable method is the integrated Password Generator in Password Depot. Select the maximum permitted length and all allowed character types to Entropy (randomness) to maximize. Longer, random passwords are almost always stronger than short, “clever” ones.

A key advantage: You do not need to remember the complex passwords generated by the generator–they are securely stored in an encrypted password vault and available whenever you need them. Password Depot reduces the risk of data loss through automatic backups of your databases, which you can store locally, on external media, on servers, or in the Cloud.

Weak passwords as a security risk

Which passwords are especially popular–and insecure–in this country? The annual top list from the Hasso Plattner Institute (HPI) has shown for years that simple number sequences such as “123456” or terms like “password” or “Passwort” are still frequently used and can be extremely quickly cracked. Such passwords leave the door wide open to attackers.

In addition to their general weakness, many people reuse the same password across multiple services. Password reuse means that a single leak can put several accounts at risk.

Is my password secure?

Weak passwords are an open invitation to identity theft. In brute-force and dictionary attacks, common combinations (including typical patterns such as “abcde,” “qwertz,” and “Passwort1”) are tested at high speed. Password Depot supports you with a quality analysis for each entry and warns you about easily guessed patterns or passwords that are too short.

Check your entries regularly in Password Depot: Intelligent checks help identify and replace overly weak passwords.

Generate secure passwords–with Password Depot

Screenshot of the Password Depot Windows client: password analysis with strength rating and password generator with configurable length and character sets.
Password analysis & generator in the Windows client

Especially in companies passwords should meet defined quality requirements. Password Depot’s password generator creates strong, random passwords and stores them in encrypted form–with AES-256 (Rijndael), an internationally standardized method recognized as highly robust.

When logging in–for example, to email inboxes, bank accounts, or web forms–Password Depot can enter login credentials automatically and securely insert. If you want to look up a password in plain text, you will find it only in the vault accessible to you.

How often should passwords be changed?

Current expert recommendation: No forced, regular password changes without cause. Change passwords if there is a specific suspicion (e.g. data leak, phishing, unusual logins), if you have shared a password, if accounts are particularly sensitive, or if you have used weak/short passwords. In addition, consistently rely on multi-factor authentication (MFA) and–where available–modern methods such as passkeys.

Password Depot can remind you to renew specific entries when needed: simply fill in the “Valid until” field and define individual deadlines for each entry.

Tips for creating secure passwords

If, in exceptional cases, you create a password without a generator, these guidelines will help:

  • Length matters: Use as many characters as allowed–at least 12–16 is a practical minimum. Every additional character noticeably increases security.
  • Randomness over patterns: No repetitions or patterns (“aaaaa”, “ababab”, “20242025”).
  • Character variety: Use uppercase and lowercase letters, numbers, punctuation marks, and special characters. If you do not use all character types, make the password correspondingly longer.
  • No sequences: Avoid sequences and keyboard patterns such as “12345”, “abcde”, “qwertz”.
  • No “leetspeak”:” Predictable substitutions such as “P@ssw0rd” are well known to attackers and offer little protection. Instead, rely on Length and randomness.
  • No personal data: No names, dates of birth, phone numbers, license plate numbers, etc.
  • No personal preferences: No favorite foods/clubs/places (“PizzaSalami,” “BayernMunich,” “LakeConstance”).
  • No pure dictionary words: A single familiar word–even if it is long–is vulnerable to dictionary attacks. Better: Passphrases made up of several random words plus separators/numbers.
  • Unique for each account: Use every account with a different password–never reuse passwords.

Tips for your master password in Password Depot

You only need to remember one password: your master password. Proven effective are individual passphrases, for example three to five random words with separators and optional numbers/special characters. Avoid proverbs and well-known mnemonic phrases.

Example of an individual passphrase (for illustration only, please do not use it): “I use secure passphrases in Password Depot and have done so for 10 years” ⇒

Passphrase example

I#use#secure#passphrases#for#10#years

(adapt further if needed).

Also possible is the mixing of words and numbers–however, the numbers should no easily guessable information should be used. As a general rule: Length + randomness beat tricks.

Summary

  • Password changes in the event of security incidents, suspected compromise, or shared/insecure passwords – no regular forced changes without cause.
  • Maximum length should be used, ideally with a generator.
  • Use all permitted character types or, if not possible, significantly increase the length.
  • No dictionary words on their own, no names/numbers, no keyboard patterns.
  • No reuse of identical or similar passwords across different services (see the guide).
  • Password manager such as Password Depot – then you only need to remember a single master password.
  • Enable MFA (and use passkeys where available).

Sources (selection)

Understanding brute-force attacks

Find out why length matters – with calculation examples and countermeasures.

Brute-force attacks