A password should be difficult to guess and different for every account. Reusing one password creates a chain risk: if one service is breached, attackers may try the same credential elsewhere.
Use Unique Credentials
A password manager can create and store a different random password for each website. Protect the manager account with a strong, unique master password and enable multi-factor authentication where available. Keep recovery codes somewhere safe and separate from the device they protect.
When a Passphrase Helps
A passphrase combines several randomly selected words. More independent random words generally make it harder to guess, while making the secret easier to type than a random string of the same length. A phrase or quotation you already know is not random and may be easier to guess than it seems.
Use the Passphrase Generator to create a random phrase or the Password Generator for a random password. Do not reuse generated credentials or share them through chat or email.
Check a Password Safely
Avoid entering a real password into an unfamiliar checker. A local-only strength estimate can help evaluate length and composition, but it cannot prove that a password has never appeared in a breach. If you suspect exposure, change it on the affected service and anywhere it was reused.