Comparing entropy honestly
Strength comes down to entropy: how many guesses an attacker needs on average. A random 16-character password from upper, lower, digits, and symbols has about 95¹⁶ possibilities — roughly 105 bits of entropy. A passphrase of four words drawn randomly from a 7,776-word list (the classic Diceware list) has 7,776⁴ possibilities — about 52 bits.
So per unit of effort, random characters pack more entropy into less space. But that comparison misses the point: memorability is a security feature. A 105-bit password written on a sticky note or reused everywhere is weaker in practice than a 52-bit passphrase you actually use correctly and uniquely.
When you must memorize it
Humans memorize a tiny number of secrets: your password manager's master password, your phone unlock, maybe full-disk encryption. For these, passphrases win decisively. "correct horse battery staple" is typable, sayable, and memorable after a day of use; "J7#qL9!vZ2@kP4&x" is none of those.
Rules for a good memorized passphrase:
- Random words, not a sentence. Attackers try song lyrics, quotes, and grammar patterns. Roll dice or use a generator.
- Four words minimum; five or six for a master password. Each Diceware word adds ~12.9 bits.
- Add a personal, non-obvious twist — a separator character, a capital in an odd place — that you will remember but is not guessable from your life.
When nobody memorizes it
For the other 99% of accounts, nobody should memorize anything. Generate a long random string with our password generator, save it in your password manager, and never look at it again. Here random passwords win: maximum entropy per character, no linguistic patterns, and memorability is irrelevant.
A 20-character generated password (~131 bits) is effectively uncrackable by brute force, and because it is unique per site, breaches elsewhere cannot touch the account. This is the setup security professionals actually use.
How many words is enough?
- 4 words (~52 bits): fine for low-stakes secrets with rate-limited logins.
- 5 words (~65 bits): solid for a password manager master password.
- 6 words (~78 bits): excellent — comparable to a strong random password, still memorable.
- 7+ words: diminishing returns for memorized secrets; consider whether a generated password in a manager fits better.
One more consideration: some sites cap password length at 16 or 20 characters. A six-word passphrase will not fit; generate a shorter random password instead. Always check the site's limits before committing to a scheme.
Generating truly random words: the dice method
Humans are terrible random-word pickers — we favor common words, recent experiences, and grammatical patterns attackers model. The classic fix is Diceware: roll physical dice to index into a word list. Five dice give a number from 11111 to 66666; look it up on a 7,776-word list; repeat for each word. Five rolls per word, six words, thirty rolls total — about five minutes for a master passphrase you will use for years.
Why physical dice? They are auditable randomness you can see and trust — no software to backdoor, no seed to leak. Casino-grade dice are ideal (balanced), but any dice work. If dice feel theatrical, a reputable generator using crypto.getRandomValues() is the digital equivalent; what matters is that you do not choose the words.
One caution: some "passphrase generators" online pick from tiny word lists or, worse, assemble grammatical sentences. Verify the method: each word should come from a list of at least ~7,700 words via a cryptographic random source. Then memorize the result with spaced repetition — write it, type it ten times today, five tomorrow, and it will stick.
Next steps: learn how to create strong passwords in general, or bust the myths in password security myths, debunked.