Making Strong Passwords

Life Skills Interactive lesson Free to play

Making strong passwords is the practice of choosing login secrets that are long, unpredictable and unique to each account. A password is what proves an account belongs to you, so anything short, common or guessable โ€” 'password123', a pet's name, a birthday โ€” can be broken by software that tries millions of combinations every second. Length matters far more than adding a stray capital letter: each extra character multiplies the guessing work.

In Singapore, primary-school children already sign in to Student Learning Space, school Google accounts, games and messaging apps, so the habit is worth building early. The most practical method is a passphrase: three or four unrelated words joined together with a number and a symbol, which is long enough to resist guessing but easy for a child to picture and remember.

The other half of password safety is behaviour. Personal facts a classmate could look up make weak passwords; reusing one password across sites means a single leak opens every account; and no legitimate school, game or shop will ever ask for a password by message โ€” that request is phishing.

โ–ถ Play the lesson โ€” free, no signup

Want to create your own Spark? Sign up free โ€” type any skill and LearnBuddy builds you a playable lesson.

Sign up free to create your own Spark

What this Spark covers

Frequently asked questions

What makes a password strong?
Length is the biggest factor โ€” aim for at least 12 to 16 characters. A strong password also mixes upper and lower case letters, numbers and symbols, avoids real names or dictionary words on their own, and is used on one account only.
Is a passphrase like 'purple-turtle-noodle7!' really safer than 'P@ssw0rd1'?
Yes. 'P@ssw0rd1' is short and follows a substitution pattern that guessing software checks first, so it falls quickly. Four unrelated words give far more possible combinations and are easier for a child to recall without writing them down.
Why can't my child use the same password for every account?
If any one website is hacked and its passwords leak, attackers try that same email-and-password pair on other services โ€” a technique called credential stuffing. One password per account keeps a single leak contained.
Should a child use their name, birthday or favourite football team in a password?
No. Details that a classmate, relative or anyone browsing social media could find out are among the first things a guesser tries. Choose words with no connection to the child's real life.
Someone messaged my child asking for their game password โ€” what should we do?
Do not reply, and never share the password. Real games, schools and shops never ask for passwords through chat, email or SMS; that is phishing. Block the sender, tell a trusted adult, and change the password if it was already given out.

More Sparks like this

Loved this Spark? Sign up free for AskBuddy AI tutoring, past-year papers, and unlimited Sparks.

Sign up free โ†’