Coffee-River-Mountain-47! — long, memorable, hard to crack.Never reuse passwords across sites. Use a password manager like Bitwarden (free & open source).
Why password strength matters
Password strength rules that actually work
Length matters more than complexity — a longer passphrase is harder to crack than a short password stuffed with symbols. Aim for at least 12–16 characters and avoid reusing the same password across banking and UPI apps.
How breach checks work
PhishGuard checks your password against databases of previously leaked credentials using Have I Been Pwned's k-anonymity API — your full password is never sent or stored anywhere.
k-anonymity explained (why your password stays private)
Your password is hashed locally, and only the first 5 characters of that hash are sent to the breach database — the match happens on your device, so your actual password never leaves your browser.
Weak passwords are cracked in seconds using dictionary attacks. A 6-character password has ~1 billion combinations — a modern GPU cracks it in under 1 second. A 16-character random password has 10³² combinations — takes millions of years.
India-specific risks
Common weak passwords in India: mobile numbers, birthdates, "India@123", "Abcd1234". Data breaches at Dominos, MobiKwik, Air India exposed millions of Indian credentials. Check yours now.