Last updated:

Best Wi-Fi Password Length - Safe and Easy to Remember

About a 9-minute read

Ever visited a friend's house and typed in the long string of letters and numbers printed on the back of their router? That length was not picked at random. Too short and it gets cracked. Too long and it is a pain to type. This article looks for the sweet spot from two directions, what the standard actually allows and how long each length takes to crack.

Wi-Fi Password Length Limits

Encryption StandardMinimum LengthMaximum LengthRecommended LengthWhere It Stands as of 2026
WEP (old)5 characters (10 hex digits)13 characters (26 hex digits)Do not useCracked in minutes with off-the-shelf tools
WPA2-Personal8 characters63 characters12-16 charactersWidely used on home networks
WPA3-Personal8 characters63 characters12-16 charactersStrongest against guessing attacks

That 8-to-63 window is not something each manufacturer decided. It is written into the standard, so the ceiling of 63 characters is the same on every router. If your router refused a 64-character passphrase, that is the rule working as intended, not a bug.

WEP shipped with the first edition of 802.11 in 1997, and the IEEE formally deprecated it in 2004. The problem was never the key length but the design itself, which is why even a 13-character WEP key falls in minutes. If your router still offers WEP in its menu, the right move is simply not to pick it. Stick with WPA2 or WPA3 and set a password of at least 8 characters.

WPA2 and WPA3 Minimum and Recommended Length

For both WPA2-Personal and WPA3-Personal, the technical minimum password length is 8 characters and the maximum is 63 characters. This 8-to-63 range comes from the IEEE 802.11 standard, which defines the pre-shared key passphrase (the SAE password in WPA3, the PSK passphrase in WPA2) as an ASCII string of 8 to 63 printable characters. The standard also allows the key to be entered directly as 64 hexadecimal digits instead of a passphrase, which is why some router screens accept that one specific longer form. Routers reject anything shorter than 8, so 8 is the hard floor on both standards.

The minimum and the recommended length are not the same thing. Eight characters merely satisfies the standard - it does not make a network safe. The recommended length for everyday use is 12 to 16 characters mixing upper case, lower case, digits, and symbols. WPA3 is more resistant to offline brute-force attacks than WPA2 because its SAE handshake (Simultaneous Authentication of Equals) blocks the offline dictionary attacks that WPA2's 4-way handshake is vulnerable to. Even so, weaknesses in that design have been reported since its release, and a short passphrase can still be guessed through online attempts. The 12-to-16-character recommendation applies equally to WPA3, because length is the part you control no matter what the handshake does.

StandardMinimum (technical)MaximumRecommendedKey Attack Resistance
WPA2-Personal8 characters63 characters12-16 charactersVulnerable to offline dictionary attacks if short
WPA3-Personal8 characters63 characters12-16 charactersSAE is designed to block offline brute-force, but weaknesses have been reported, so still avoid short passphrases

Password Length vs. Time to Crack

Password LengthCharacters UsedPossible CombinationsTime to Try Every Combination
8 chars (digits only)0-9100 millionAbout 2 minutes
8 chars (lowercase + digits)a-z, 0-9About 2.8 trillionAbout 1 month
8 chars (mixed case + digits + symbols)95 typesAbout 6.6 quadrillionAbout 210 years
12 chars (mixed case + digits)62 typesAbout 3.2 sextillionAbout 100 million years
16 chars (mixed case + digits)62 typesAbout 48 octillionAbout 1.5 quadrillion years

The time column is a worked example under one stated assumption, a rig that tests one million guesses per second running through every combination. The right guess turns up halfway through on average, so treat the figures as roughly twice the typical wait. Any number written without an assumption behind it cannot be compared against anything. Make the rig a thousand times faster and every figure shrinks a thousandfold, yet 12 characters still leaves about 100,000 years. That gap is the whole reason length is the lever worth pulling.

One million guesses per second sounds modest, and there is a reason for that. WPA2 and WPA3 do not use your passphrase as the key directly. They run it through a repeated calculation, 4,096 rounds of HMAC-SHA1, before deriving the key, so each single attempt costs real work and the same hardware gets through fewer of them. The value mixed in during that step is the SSID (network name), which means a common network name makes it easier to reuse a precomputed table against you. Name and length are not separate defenses. They work as a pair.

The standard you run matters too. With WPA2, recording one connection handshake is enough, and everything after that can be tried locally at whatever speed the attacker's hardware allows. WPA3 replaced that with a scheme where each guess requires another exchange with the access point, so carrying a recording home and grinding on it does not work the same way. As covered in Password Length and Security, adding length buys more per unit of effort than adding character types, and Wi-Fi is no exception.

How to Judge the Default Password on Your Own Router

What to Look AtSign That It Is WeakWhat to Do About It
LengthExactly 8 characters, the standard's floorChange it to 12 characters or more
Characters usedDigits onlyChange it, at the speed shown in the first row of the table above
Readability tweaksA short string that avoids look-alike charactersMake up the difference with length
Where it is printedOn a label on the unit, or on a card in the boxStop keeping the router where visitors can read it
Whether it was ever changedStill exactly as it shippedChange it once, during initial setup

Default password lengths differ by manufacturer and by model, and there is no published catalog that covers them reliably. Rather than trying to remember which brand uses how many characters, read the label in front of you against the points above. Exactly 8 characters means you are sitting on the standard's floor, so that one is the first to change. A random string of around 13 characters is long enough, though anyone who can see the unit can still read it. If your router sits where guests walk past, swapping in a long phrase you can actually remember is worth the five minutes.

One change is enough. A long password left alone protects you better in practice than a mediocre one rotated on a schedule. The US NIST digital identity guidelines (SP 800-63B, fourth edition) take the same line, prohibiting forced periodic changes and favoring length over composition rules. Those guidelines cover authentication for online services rather than Wi-Fi settings as such, but the reasoning carries over.

How to Create a Password That Is Both Safe and Memorable

MethodExampleLengthMemorabilitySecurity
A sentence you likeILoveSushi2026!15 charactersHighHigh
Three random wordscat-rain-pizza14 charactersHighHigh
Initials + numbersMfis2026Bkb!12 charactersMediumHigh
Random generatorxK9#mP2$vL5@12 charactersLowHighest

The "three random words" method is what the UK National Cyber Security Centre (NCSC) suggests to ordinary users. Three words get you the length, and because each one means something on its own, you can actually hold it in your head. The NCSC attaches conditions, though. Avoid words that are easy to guess, meaning common words and keyboard runs, and avoid anything tied to you, such as family or pet names, the team you follow, or where you live. "cat-rain-pizza" works because the three words have nothing to do with each other, so knowing the owner does not help you guess it.

A Wi-Fi password can run longer than one you type every day, because the device remembers it after the first entry. The reason this article settles on 12 to 16 characters is that this is roughly the upper limit of what you can memorize and type by hand. If you keep it in a password manager instead, 20 characters or more is perfectly practical, and you are free to use the full 63 the standard allows.

Ways to Share Your Wi-Fi Password with Friends

MethodConvenienceSecuritySupported Devices
QR code sharingHighHighAndroid / iPhone
iPhone Wi-Fi sharingHighHighiPhone to iPhone
Tell them out loudMediumMediumAll devices
Write it on paperLowLowAll devices
Send via LINEHighLowAll devices

What makes a QR code safe is that you never hand over the string itself. The scanning device just receives the settings, so there is nothing to mishear or mistype either. It also removes the one real drawback of a long password, that you cannot read it out loud. The safety only holds for the way you use it, though, which is showing it on a screen and closing it afterwards. Print it and pin it to the wall and you are back to handing someone a slip of paper. Sending it over a messaging app such as LINE is weak for the same reason, because the string stays in the chat history where anyone who later picks up the phone can read it.

If you find yourself giving the password out often, check whether your router can run a separate guest network. Share a shorter guest password and leave the one your own devices use long, and you get both the convenience and the strength. Reviewing your Wi-Fi SSID naming practices at the same time covers you from both sides, the name and the length.

Frequently Asked Questions

Is an 8-character Wi-Fi password safe?
Not really. Eight characters is only the technical minimum for WPA2 and WPA3 - an 8-digit number-only password has just 100 million combinations and can be brute-forced in seconds. Use 12-16 characters mixing upper case, lower case, digits, and symbols.
What is the maximum Wi-Fi password length for WPA2 and WPA3?
63 characters. The IEEE 802.11 standard defines the pre-shared key passphrase as 8 to 63 printable ASCII characters, and both WPA2-Personal and WPA3-Personal follow this range.

Share this article