Last updated:
Best Wi-Fi Password Length - Safe and Easy to Remember
Ever visited a friend's house and typed in the long string of letters and numbers printed on the back of their router? That length was not picked at random. Too short and it gets cracked. Too long and it is a pain to type. This article looks for the sweet spot from two directions, what the standard actually allows and how long each length takes to crack.
Wi-Fi Password Length Limits
| Encryption Standard | Minimum Length | Maximum Length | Recommended Length | Where It Stands as of 2026 |
|---|---|---|---|---|
| WEP (old) | 5 characters (10 hex digits) | 13 characters (26 hex digits) | Do not use | Cracked in minutes with off-the-shelf tools |
| WPA2-Personal | 8 characters | 63 characters | 12-16 characters | Widely used on home networks |
| WPA3-Personal | 8 characters | 63 characters | 12-16 characters | Strongest against guessing attacks |
That 8-to-63 window is not something each manufacturer decided. It is written into the standard, so the ceiling of 63 characters is the same on every router. If your router refused a 64-character passphrase, that is the rule working as intended, not a bug.
WEP shipped with the first edition of 802.11 in 1997, and the IEEE formally deprecated it in 2004. The problem was never the key length but the design itself, which is why even a 13-character WEP key falls in minutes. If your router still offers WEP in its menu, the right move is simply not to pick it. Stick with WPA2 or WPA3 and set a password of at least 8 characters.
WPA2 and WPA3 Minimum and Recommended Length
For both WPA2-Personal and WPA3-Personal, the technical minimum password length is 8 characters and the maximum is 63 characters. This 8-to-63 range comes from the IEEE 802.11 standard, which defines the pre-shared key passphrase (the SAE password in WPA3, the PSK passphrase in WPA2) as an ASCII string of 8 to 63 printable characters. The standard also allows the key to be entered directly as 64 hexadecimal digits instead of a passphrase, which is why some router screens accept that one specific longer form. Routers reject anything shorter than 8, so 8 is the hard floor on both standards.
The minimum and the recommended length are not the same thing. Eight characters merely satisfies the standard - it does not make a network safe. The recommended length for everyday use is 12 to 16 characters mixing upper case, lower case, digits, and symbols. WPA3 is more resistant to offline brute-force attacks than WPA2 because its SAE handshake (Simultaneous Authentication of Equals) blocks the offline dictionary attacks that WPA2's 4-way handshake is vulnerable to. Even so, weaknesses in that design have been reported since its release, and a short passphrase can still be guessed through online attempts. The 12-to-16-character recommendation applies equally to WPA3, because length is the part you control no matter what the handshake does.
| Standard | Minimum (technical) | Maximum | Recommended | Key Attack Resistance |
|---|---|---|---|---|
| WPA2-Personal | 8 characters | 63 characters | 12-16 characters | Vulnerable to offline dictionary attacks if short |
| WPA3-Personal | 8 characters | 63 characters | 12-16 characters | SAE is designed to block offline brute-force, but weaknesses have been reported, so still avoid short passphrases |
Password Length vs. Time to Crack
| Password Length | Characters Used | Possible Combinations | Time to Try Every Combination |
|---|---|---|---|
| 8 chars (digits only) | 0-9 | 100 million | About 2 minutes |
| 8 chars (lowercase + digits) | a-z, 0-9 | About 2.8 trillion | About 1 month |
| 8 chars (mixed case + digits + symbols) | 95 types | About 6.6 quadrillion | About 210 years |
| 12 chars (mixed case + digits) | 62 types | About 3.2 sextillion | About 100 million years |
| 16 chars (mixed case + digits) | 62 types | About 48 octillion | About 1.5 quadrillion years |
The time column is a worked example under one stated assumption, a rig that tests one million guesses per second running through every combination. The right guess turns up halfway through on average, so treat the figures as roughly twice the typical wait. Any number written without an assumption behind it cannot be compared against anything. Make the rig a thousand times faster and every figure shrinks a thousandfold, yet 12 characters still leaves about 100,000 years. That gap is the whole reason length is the lever worth pulling.
One million guesses per second sounds modest, and there is a reason for that. WPA2 and WPA3 do not use your passphrase as the key directly. They run it through a repeated calculation, 4,096 rounds of HMAC-SHA1, before deriving the key, so each single attempt costs real work and the same hardware gets through fewer of them. The value mixed in during that step is the SSID (network name), which means a common network name makes it easier to reuse a precomputed table against you. Name and length are not separate defenses. They work as a pair.
The standard you run matters too. With WPA2, recording one connection handshake is enough, and everything after that can be tried locally at whatever speed the attacker's hardware allows. WPA3 replaced that with a scheme where each guess requires another exchange with the access point, so carrying a recording home and grinding on it does not work the same way. As covered in Password Length and Security, adding length buys more per unit of effort than adding character types, and Wi-Fi is no exception.
How to Judge the Default Password on Your Own Router
| What to Look At | Sign That It Is Weak | What to Do About It |
|---|---|---|
| Length | Exactly 8 characters, the standard's floor | Change it to 12 characters or more |
| Characters used | Digits only | Change it, at the speed shown in the first row of the table above |
| Readability tweaks | A short string that avoids look-alike characters | Make up the difference with length |
| Where it is printed | On a label on the unit, or on a card in the box | Stop keeping the router where visitors can read it |
| Whether it was ever changed | Still exactly as it shipped | Change it once, during initial setup |
Default password lengths differ by manufacturer and by model, and there is no published catalog that covers them reliably. Rather than trying to remember which brand uses how many characters, read the label in front of you against the points above. Exactly 8 characters means you are sitting on the standard's floor, so that one is the first to change. A random string of around 13 characters is long enough, though anyone who can see the unit can still read it. If your router sits where guests walk past, swapping in a long phrase you can actually remember is worth the five minutes.
One change is enough. A long password left alone protects you better in practice than a mediocre one rotated on a schedule. The US NIST digital identity guidelines (SP 800-63B, fourth edition) take the same line, prohibiting forced periodic changes and favoring length over composition rules. Those guidelines cover authentication for online services rather than Wi-Fi settings as such, but the reasoning carries over.
How to Create a Password That Is Both Safe and Memorable
| Method | Example | Length | Memorability | Security |
|---|---|---|---|---|
| A sentence you like | ILoveSushi2026! | 15 characters | High | High |
| Three random words | cat-rain-pizza | 14 characters | High | High |
| Initials + numbers | Mfis2026Bkb! | 12 characters | Medium | High |
| Random generator | xK9#mP2$vL5@ | 12 characters | Low | Highest |
The "three random words" method is what the UK National Cyber Security Centre (NCSC) suggests to ordinary users. Three words get you the length, and because each one means something on its own, you can actually hold it in your head. The NCSC attaches conditions, though. Avoid words that are easy to guess, meaning common words and keyboard runs, and avoid anything tied to you, such as family or pet names, the team you follow, or where you live. "cat-rain-pizza" works because the three words have nothing to do with each other, so knowing the owner does not help you guess it.
A Wi-Fi password can run longer than one you type every day, because the device remembers it after the first entry. The reason this article settles on 12 to 16 characters is that this is roughly the upper limit of what you can memorize and type by hand. If you keep it in a password manager instead, 20 characters or more is perfectly practical, and you are free to use the full 63 the standard allows.
Ways to Share Your Wi-Fi Password with Friends
| Method | Convenience | Security | Supported Devices |
|---|---|---|---|
| QR code sharing | High | High | Android / iPhone |
| iPhone Wi-Fi sharing | High | High | iPhone to iPhone |
| Tell them out loud | Medium | Medium | All devices |
| Write it on paper | Low | Low | All devices |
| Send via LINE | High | Low | All devices |
What makes a QR code safe is that you never hand over the string itself. The scanning device just receives the settings, so there is nothing to mishear or mistype either. It also removes the one real drawback of a long password, that you cannot read it out loud. The safety only holds for the way you use it, though, which is showing it on a screen and closing it afterwards. Print it and pin it to the wall and you are back to handing someone a slip of paper. Sending it over a messaging app such as LINE is weak for the same reason, because the string stays in the chat history where anyone who later picks up the phone can read it.
If you find yourself giving the password out often, check whether your router can run a separate guest network. Share a shorter guest password and leave the one your own devices use long, and you get both the convenience and the strength. Reviewing your Wi-Fi SSID naming practices at the same time covers you from both sides, the name and the length.
Frequently Asked Questions
- Is an 8-character Wi-Fi password safe?
- Not really. Eight characters is only the technical minimum for WPA2 and WPA3 - an 8-digit number-only password has just 100 million combinations and can be brute-forced in seconds. Use 12-16 characters mixing upper case, lower case, digits, and symbols.
- What is the maximum Wi-Fi password length for WPA2 and WPA3?
- 63 characters. The IEEE 802.11 standard defines the pre-shared key passphrase as 8 to 63 printable ASCII characters, and both WPA2-Personal and WPA3-Personal follow this range.