A strong password is unique, difficult to guess and long enough to resist automated guessing. Reusing the same password across services increases the damage from a single breach.
Use unique passwords
Use a password manager to generate and save a different password for every account. For memorable credentials, a long random passphrase can be easier to type.
Enable multi-factor authentication
Where possible, use a passkey or an authenticator-based second factor. Keep recovery codes in a secure place.
Generate locally
A browser-based password generator can create random strings without sending the result to a server, provided the implementation is trustworthy. Never share passwords in chat or email.