“correct horse battery staple” — four random words, ~51.7 bits, memorable in seconds. “Tr0ub4dor&3” — 11 characters of pain, weaker against smart guessing, forgotten by Friday. The famous xkcd #936 comparison settled the passphrase vs password debate a decade ago, and NIST agreed: length from random words beats complexity theater. But the details decide — word count, wordlist size and use case. Here they are.
Part of the password generator guide. Generate both kinds in the generator (random strings) and passphrase tool. Memory method in remembering guide.
The math: 5 words beat 12 characters
EFF's 7,776-word list: each random word ≈12.9 bits, so 4 words ≈51.7 bits, 5 words ≈64.6 bits, 6 words ≈77.5 bits. A 12-character full-pool password: ~78.7 bits. So 6 random words roughly equal 12 random characters — while remaining humanly memorizable and typable. Critical qualifier: RANDOM words. A favorite quote, lyric or proverb has a fraction of the entropy — attackers try published text first. Dice, crypto generators, or the passphrase tool — never “words that feel random.”
| Secret | Entropy | Memorizable? | Best for |
|---|---|---|---|
| 4 random words | ~51.7 bits | Yes | Low-value logins, Wi-Fi sharing |
| 5 random words | ~64.6 bits | Yes | Manager master, email |
| 6 random words | ~77.5 bits | With practice | High-value masters |
| 16 random chars | ~104.9 bits | No | Everything a manager holds |
Order-of-magnitude framing, illustrative offline ≈10B guesses/sec; online throttled far slower.
Which to use when (the split rule)
- Memorized secrets → passphrases: manager master, email, device PIN-adjacent logins, full-disk encryption. Five words minimum, story-linked for recall (absurd mental images stick).
- Stored secrets → random strings: all 200 site logins, API keys, Wi-Fi PSKs, router admins. Maximum entropy, zero memory burden — the manager's whole job.
- Shared secrets → passphrases: family Wi-Fi, streaming logins, team staging passwords. Humans transmit words without errors; dictating 16 symbols over the phone fails.
- Never: song lyrics, quotes, keyboard patterns or “passphrase-style” phrases you invented — non-random word choice collapses entropy toward single digits of effective bits against smart attacks.
Diceware in 2 minutes (trustable randomness by hand)
Distrust software? Roll physical dice: five rolls pick one of 7,776 EFF words; repeat 5–6 times. Dice have no code to backdoor and no memory to leak — the gold standard paranoids and experts agree on. Our passphrase tool demonstrates the concept with a compact built-in wordlist (fine for practice and low-value secrets — for real masters, use physical dice or a 20+ character secret from the generator). Either way: keep the first draw — re-rolling “ugly” words injects human bias that shrinks entropy. Write the result on paper until memorized, then destroy the paper; never photograph it.
Non-English passphrases (untapped entropy)
Wordlists exist beyond English — and attackers' dictionaries skew English-first. Hindi, Spanish or Tamil wordlists from reputable sources add equivalent bits per word (~12.9 at 7,776 entries) while dodging English-centric guessing. Rules: use a published uniform list (never your own vocabulary — personal word choice is predictable), keep words space-separated for entry, and confirm every login form accepts Unicode (legacy bank forms sometimes mangle it — test before committing a master to Devanagari). Mixed-language draws are fine if uniformly generated, but single-list draws keep the math clean. Whatever the language, randomness source matters more than tongue: dice or crypto.getRandomValues, first draw kept.
General information only, not security advice. Generate offline, store in a manager, enable MFA on email/bank. If you lose your master password it cannot be recovered by us.