How Long Should a Wi-Fi Password Be?
How long should a Wi-Fi password be for real security? Longer than your router asks for. The box says 8 characters minimum. That minimum was set for compatibility, not for survival, and on WPA2 it is nowhere close to enough.
Here is the scene that made me write this. A friend got a new router, proudly typed an 8 character password with a capital letter and a number, and asked if it was fine. On the settings page, it was. Against an attacker parked outside with a laptop, it is not. The threat is specific and well understood: on WPA2, someone can capture your handshake from the air and then crack it offline, at home, with no time limit and no lockout timer. That single fact is why the length answer for Wi-Fi is different from the length answer for a website login.
How long should a Wi-Fi password be: the 8 to 63 rule
The spec behind this is IEEE 802.11i: a WPA2 or WPA3 passphrase is an 8 to 63 ASCII character sequence. Below 8, the router refuses it. Above 63, extra characters get truncated, silently in some firmware. Inside that range, anything is accepted, and acceptance tells you nothing about safety.
The length that actually matters depends on which protocol your network runs:
| Protocol | Length range | My floor | Why |
|---|---|---|---|
| WPA2 | 8 to 63 | 16 characters, random | Offline handshake attacks; attacker can guess forever |
| WPA3 | 8 to 63 | 12 characters, random | SAE handshake blocks offline cracking, but length is cheap |
| Mixed WPA2/WPA3 | 8 to 63 | 16 characters, random | The oldest device on the network sets the real bar |
My home default is 20 fully random characters. That lands around 120 bits of entropy, which is effectively uncrackable with any hardware you can rent. And notice what I did not say: nothing about symbols, capital letters, or clever substitutions. Length plus randomness does the whole job. A 20 character random lowercase password beats a 10 character "complex" one, and it is far easier to type on a TV remote.
The dictionary-word trap at any length
Long is not the same as random. A 20 character password like compartmentalization is one dictionary word, and cracking tools try dictionary words first. This is the most common way people follow the length advice and stay vulnerable: they pick a long word instead of a random string.
The fix is boring. Generate, do not compose. Use a generator that pulls from your browser's cryptographic randomness and accept what comes out. Nobody types a Wi-Fi password daily; you type it once per device, then the device remembers it. The small pain of entry is a one-time cost for years of protection.
Do not let the symbols lock you out of your own devices
There is a second trap, and it is dumber. WPA passwords accept a wide set of special characters, and it is tempting to load the password with them for extra "complexity." Then the smart TV refuses to connect. Or the game console chokes. Or a cheap IoT plug fails silently.
Some router firmware and client devices handle unusual characters badly. The safe practice I landed on: stick to common punctuation like !@#$%&*+-_=.? and test the new password on your fussiest device before you commit. If anything struggles, drop the symbols entirely and add four more random characters instead. Length is doing the real work anyway.
The guest problem, solved properly
The real reason people keep Wi-Fi passwords short is guests. Nobody wants to dictate 20 random characters over the phone. Two things fix this without weakening the password.
First, generate a Wi-Fi QR code. Guests point their phone camera at it and connect without typing a single character. Second, if your router supports a guest network, turn it on and put visitors and smart home gadgets on it, separate from the laptops and storage drives on your main network. Then you can rotate the guest password freely without touching anything else.
And one last thing that is free: change the router's admin password too. The Wi-Fi key and the admin login protect different layers, and most routers still ship with the same default credentials printed on a sticker.
Frequently asked questions
What is the minimum Wi-Fi password length?
8 characters is the enforced minimum for WPA2 and WPA3, and the maximum is 63. But 8 is a floor for compatibility, not security. On WPA2, anything under 16 characters is easy for an attacker with a captured handshake to crack offline.
Is 20 characters enough for a Wi-Fi password?
Yes, if the characters are random. A fully random 20 character password has roughly 120 bits of entropy, which is effectively uncrackable with current hardware. Predictability matters more than length: a 20 character dictionary word like "compartmentalization" is far weaker.
Should I use special characters in my Wi-Fi password?
Stick to common ones like !@#$%&*+-_=.?. Exotic symbols can break logins on smart TVs, consoles, and older devices whose firmware handles character encoding poorly. Extra length beats exotic characters anyway.
Does WPA3 let me use a shorter password?
WPA3's SAE handshake protects against offline dictionary attacks, so it is more forgiving than WPA2. Still aim for at least 12 characters, and 16 if any device on the network uses WPA2, because the weakest link sets the rule.
How do I share a long Wi-Fi password with guests?
Generate a Wi-Fi QR code so guests scan and connect without typing. Most modern phones support this from the camera app. Put guests on a separate guest network if your router supports one, so the main password stays private.
Related reading: Diceware Passphrase vs Random Password: Which One Should You Actually Use? · How Many Words Does Your Passphrase Need? Entropy Math, Worked Out · Can You Put Spaces in a Password? Yes, and Most Sites Should Accept Them