I hear so often that people complain that someone managed to "break" into their Facebook or email account. When I speak to them and ask them questions I soon find out that it was just a matter of time until their password was figured out. Here is a list of don'ts and Dos that hopefully will help keeping your "private" stuff really private.
Don'ts
Never ever use you user name as the password. That is probably one of the first thing people try. Other things that peopletry as passwords are Calendar months i.e. March or week days i.e. Monday. you should also never use dates as passwords. So if you are thinking about using your birthday as password forget it think again. When choosing a password never use a sequence ie 22222222 or 12345678 or qwertyu.
If your password is in the dictionary of any language then there is a very good chance that some hacker will be able to break into your account.
Password should be kept secret. Don't share them with anyone and don't write them down. If you have to give someone your password for whatever reason, make sure you change it asap after the person has finished with whatever he/she was doing.
I have friends that use the same password on all websites that they use. Does that make sense? No! If one account is broken into all of them are broken into. Which leads us to the Does.
Dos
Make sure you use different passwords for different websites. make it as difficult as possible for anyone to simply guess your password. Use a mixture of UPPERCASE and lowercase letters and as many numbers and symbols (where allowed) as possible. Make sure you your chosen password is at least 8 characters long and remember the longer the better.
Microsoft has a website where you can check your password strength. (HERE) You might be surprised that your password is very weak.
Change your password regularly. Every month if possible but at least every 90 days.
I hope this will help you to keep your stuff save and secure.