# Wie erstelle ich ein sicheres Passwort? Schwache Passwörter sind einer der häufigsten Gründe für gehackte Konten. Mit den richtigen Techniken kannst du deine Online-Konten zuverlässig schützen – ohne dir komplizierte Zeichenkombinationen merken zu müssen. ## Was macht ein Passwort sicher? Ein sicheres Passwort zeichnet sich durch **Entropie** aus – das ist das Maß für seine Zufälligkeit und Unvorhersehbarkeit. Je mehr Entropie, desto länger braucht ein Angreifer, um das Passwort zu knacken. Folgende Faktoren erhöhen die Sicherheit: - **Länge**: Jedes zusätzliche Zeichen multipliziert die Anzahl möglicher Kombinationen exponentiell - **Zeichenvielfalt**: Groß- und Kleinbuchstaben, Ziffern und Sonderzeichen vergrößern den Zeichenraum - **Zufälligkeit**: Keine Wörter aus dem Wörterbuch, keine Muster wie „1234" oder „qwerty" ## Die häufigsten Fehler ### Persönliche Informationen Geburtsdaten, Namen von Haustieren oder Lieblingsmannschaften sind leicht zu erraten – besonders, wenn deine Social-Media-Profile öffentlich sind. ### Passwörter wiederverwenden Wird eine Website gehackt, probieren Angreifer kompromittierte Passwörter sofort auf anderen Diensten aus (sogenannte „Credential Stuffing"-Angriffe). Jedes Konto braucht ein einzigartiges Passwort. ### Muster statt Zufälligkeit `Passwort123!` erfüllt technisch alle Anforderungen – aber Angreifer kennen solche Muster und testen sie zuerst. ## Drei bewährte Methoden ### 1. Klassisches Zufallspasswort Ein mit `crypto.getRandomValues()` generiertes Passwort aus 20+ Zeichen mit Groß- und Kleinbuchstaben, Ziffern und Symbolen hat über 130 Bit Entropie. Das entspricht Milliarden von Jahren Crackzeit – selbst mit modernster Hardware. Beispiel: `nX7!kQr3mVp9wL2$jY8t` ### 2. Passphrase (Diceware) Eine Passphrase aus 5–6 zufällig gewählten Wörtern ist oft sicherer als ein kurzes, komplexes Passwort – und deutlich leichter zu merken. Beispiel: `tiger-atlas-blume-fenster-kaffee` Mit 5 Wörtern aus einer 7776-Wörter-Liste erreichst du über 64 Bit Entropie. Passphrases werden von Sicherheitsexperten wie dem NIST ausdrücklich empfohlen. ### 3. Passwort-Manager verwenden Der einfachste Weg zu sicheren Passwörtern: Ein Passwort-Manager (z. B. Bitwarden, 1Password, KeePass) generiert und speichert für jedes Konto ein einzigartiges, starkes Passwort. Du musst dir nur noch ein einziges Master-Passwort merken. ## Entropie verstehen | Methode | Zeichen/Wörter | Entropie | | -------------------- | -------------- | --------- | | 8-Zeichen klassisch | 8 | \~52 Bit | | 12-Zeichen klassisch | 12 | \~78 Bit | | 20-Zeichen klassisch | 20 | \~130 Bit | | Passphrase 4 Wörter | 4 | \~51 Bit | | Passphrase 5 Wörter | 5 | \~64 Bit | | Passphrase 6 Wörter | 6 | \~77 Bit | Als Faustregel gilt: **Mindestens 60 Bit** für normale Konten, **80+ Bit** für wichtige Konten wie E-Mail und Banking. ## Sofort loslegen Der pwgen.de Generator erstellt alle Typen direkt in deinem Browser – kein Passwort verlässt dein Gerät. Wähle einfach deinen Typ, passe die Einstellungen an und kopiere das Ergebnis in deinen Passwort-Manager. # How to Create a Strong Password Weak passwords are one of the most common causes of hacked accounts. The good news: with the right approach, you can protect your accounts reliably — without memorising complicated strings of characters. ## What Makes a Password Strong? A strong password has high **entropy** — a measure of its randomness and unpredictability. The higher the entropy, the longer it takes an attacker to crack it. Key factors that increase security: - **Length**: Every additional character multiplies the number of possible combinations exponentially - **Character variety**: Uppercase and lowercase letters, digits, and symbols expand the character space - **Randomness**: No dictionary words, no patterns like "1234" or "qwerty" ## Common Mistakes to Avoid ### Personal information Birthdates, pet names, or favourite sports teams are easy to guess — especially if your social media profiles are public. ### Reusing passwords When a website is breached, attackers immediately try compromised credentials on other services (known as "credential stuffing"). Every account needs a unique password. ### Patterns instead of randomness `Password123!` technically meets most requirements — but attackers know these patterns and test them first. ## Three Proven Methods ### 1. Classic random password A password generated with `crypto.getRandomValues()` consisting of 20+ characters with uppercase and lowercase letters, digits, and symbols has over 130 bits of entropy. That translates to billions of years of cracking time — even with modern hardware. Example: `nX7!kQr3mVp9wL2$jY8t` ### 2. Passphrase (Diceware) A passphrase made of 5–6 randomly chosen words is often more secure than a short complex password — and far easier to remember. Example: `tiger-atlas-flower-window-coffee` With 5 words from a 7,776-word list, you get over 64 bits of entropy. Passphrases are explicitly recommended by security experts including NIST. ### 3. Use a password manager The easiest path to strong passwords: a password manager (e.g. Bitwarden, 1Password, KeePass) generates and stores a unique, strong password for every account. You only need to remember one master password. ## Understanding Entropy | Method | Characters/Words | Entropy | | ----------------- | ---------------- | ---------- | | 8-char classic | 8 | \~52 bits | | 12-char classic | 12 | \~78 bits | | 20-char classic | 20 | \~130 bits | | 4-word passphrase | 4 | \~51 bits | | 5-word passphrase | 5 | \~64 bits | | 6-word passphrase | 6 | \~77 bits | As a rule of thumb: **at least 60 bits** for regular accounts, **80+ bits** for important accounts like email and banking. ## Get Started Now The pwgen.de generator creates all types directly in your browser — no password ever leaves your device. Choose your type, adjust the settings, and copy the result into your password manager.