Common guidelines for choosing good passwords are:[13][14][15][16]
Include numbers, symbols, upper and lowercase letters in passwords
Password length should be around 12 to 14 characters
Avoid passwords based on repetition, dictionary words, letter or number sequences, usernames, or biographical information like names or dates.
[edit] Examples of weak passwords
See also: Password cracking
As with any password, even in the weak category, some are weaker than others. For example, the difference in weakness between a dictionary word and a word with obfuscation (where certain letters in the password are substituted for numbers) may require a password cracking device to work a few seconds longer. The examples below illustrate various ways that weak passwords are constructed, all of which are based on very simple patterns which result in extremely low randomness: [9]
Default passwords: password, default, admin, etc
Dictionary words: chameleon, Red Sox, sandbags, etc
Wordlist with numbers: password1, deer2000, john1234, etc
Wordlist with simple obfuscation: p@assw0rd, l33th4x0r, g0ldf1sh, etc
Wordlist doubled: crabcrab, stopstop, treetree, etc
Sequences: qwerty, 12345678, euidhtns, etc
Identifiers: jsmith123, 1/1/1970, 555-1234, etc
There are many other ways a password can be weak;[17] the core principle is that a password should include real randomness and not be trivially derived from a "clever" pattern nor should passwords be mixed with information that identifies the user: that is the purpose of the user name!
[edit] Examples that follow guidelines
The passwords below are examples that follow guidelines for a strong password. Since these passwords have been publicly published, they should never be used verbatim.
4pRte!ai@3 ? mixes uppercase, lowercase, numbers, and punctuation
Tp4tci2s4U2g! ? built from a phrase that a user can memorize: "The password for (4) this computer is too (2) strong for you to (4U2) guess!" ? mixes types of character as well
BBslwys90! ? loosely based on a phrase that a user can memorize: "Big Brother is always right (right angle = 90