How Long Should a Password Actually Be for Different Types of Accounts
A reasonable baseline is 12–16 characters for most everyday accounts, and 16–20+ for high-value accounts like a primary email, password manager, or financial account — since a compromised primary email or password manager can cascade into every other account tied to it, those deserve the longest, most unique passwords.
Not every account carries equal risk if compromised, which is a reasonable basis for varying password length and care by account type, rather than treating every login identically.
Everyday, lower-stakes accounts
For accounts where a breach would be inconvenient but not seriously damaging — a forum account, a free trial signup, a newsletter login — a randomly generated 12-character password is a reasonable, low-friction baseline that's still far stronger than a typical human-chosen password of similar length.
Financial and primary accounts
For banking, primary email, and anything tied to real financial or personal risk, 16 characters or more, combined with two-factor authentication wherever available, is a more appropriate baseline — the added length costs little in a password manager but meaningfully raises the difficulty of a brute-force attempt.
The special case of a primary email and password manager
A primary email account is frequently the recovery method for every other account, and a password manager holds every other password — a compromise of either one has an outsized cascading effect compared to almost any other single account. These two specifically deserve the longest password (and strongest available second factor) of anything in a personal security setup.