Security Passwords: how to make them strong and keep track of them
Passphrases: four random words and why they beat symbols
How a passphrase gets its strength, why the words must be chosen randomly rather than by you, and how to build one you can actually remember for the few passwords you must type.
The short answer
- A passphrase beats a symbol stuffed password because random words multiply the attacker's work far faster than decoration does, and four words from a 7,776 word list means about 3.7 quadrillion possibilities.
- The words have to come from dice or a generator: a phrase you composed yourself cannot be counted, and lyrics, quotes and book lines are already inside cracking tools.
- Four random words is a solid everyday secret, but five or six is the right size for a password manager master password or disk encryption, because those face offline guessing.
- Editing the output, rerolling a word you dislike or reordering the phrase to read nicely all quietly shrink its strength.
- Passphrases belong on the three or four secrets you type from memory. Everything else should be a long random string your manager fills in for you.
A passphrase is strong for one reason only: the words were picked by something that cannot be guessed, such as dice or a generator, from a list large enough that each word is a real choice. Four words drawn that way from a standard 7,776 word list gives roughly 3.7 quadrillion equally likely phrases, which beats almost any short password a person invents. Five or six words is the sensible target for the handful of secrets you have to type from memory, because four words is thinner than it looks once an attacker has a stolen password file and a fast computer.
Where the strength actually comes from
Strength is not how odd a secret looks to a human. It is the number of equally likely possibilities someone must work through to find yours, assuming they already know exactly how you built it. That assumption is the one people skip, and it is the whole game. A serious attacker knows four word passphrases are popular, knows which word lists are published, and writes the guessing program around that.
So do the arithmetic that way. The standard dice list holds 7,776 words, one for every outcome of five six sided dice. Pick one at random and you have made one choice out of 7,776. Pick a second the same way and the total is 7,776 times 7,776. Every word multiplies:
- three words: about 470 billion phrases
- four words: about 3.7 quadrillion
- five words: about 28 quintillion
- six words: about 221 sextillion
Now compare that with the decorated password most people produce when a site demands a capital, a number and a symbol. Something like Sunfl0wer! is one common word plus three of the most predictable transformations in every cracking rule set. The base word comes from a dictionary of a few hundred thousand entries, and the decorations multiply that by a few hundred at best. It is not in the same league as four random words, and it is harder to type. The same logic runs underneath why length beats complexity in passwords generally.
Why the phrase you thought of yourself does not count
Ask a person for four random words and you will not get four random words. You will get words that go together, because that is how memory works. Nouns arrive with their usual companions, grammar sneaks in, and themes take over: pets, teams, food, the room you are sitting in. The result feels unpredictable from the inside and is nothing of the sort from the outside.
Song lyrics, film lines, scripture verses and book openings are worse still. Those strings exist in bulk as plain text, and people who crack passwords for a living feed exactly that material into their tools: lyric databases, subtitle files, quotation collections, whole public domain libraries. A phrase you can quote is a phrase someone has already indexed. The famous four word example from the web comic that popularized the idea sits in cracking lists now, precisely because it became famous.
There is a deeper problem than any particular list. If you choose the words yourself, nobody can count how many phrases you were realistically choosing between, so nobody can say how strong the result is. Randomness you can measure is worth more than cleverness you cannot.
Four words, five words or six
How many words you need depends on what happens if the secret leaks in a stolen file rather than being typed at a login page. A login page slows an attacker to a crawl with lockouts. A stolen file does not, and the speed then depends on how the site scrambled it. Old, fast hashing methods let ordinary hardware test on the order of billions of candidates per second. Deliberately slow modern methods cut that by many thousands of times, but you rarely know which one protects you.
| Secret | How it was made | Roughly how many possibilities | Honest verdict |
|---|---|---|---|
| Sunfl0wer! | One dictionary word plus standard substitutions | Tens of millions of realistic candidates | Falls in seconds offline. Only survives behind good rate limiting. |
| the sun always rises | A phrase you composed | Cannot be counted, and likely already in a phrase list | Treat as weak. Grammar and familiarity give it away. |
| otter-cabin-drift-lentil | Four words rolled from the 7,776 word list | About 3.7 quadrillion | Fine for a site that hashes properly. Days of work against a fast hash. |
| Five words, same method | Five rolls | About 28 quintillion | The right size for a password manager master password. |
| Six words, same method | Six rolls | About 221 sextillion | For disk encryption and backup keys, where an attacker can grind offline forever. |
The line worth remembering: four random words is a good everyday secret and a thin master key. Every extra word multiplies the attacker's work by another 7,776, and costs you about a second of typing.
How to generate one you can trust
The physical method: get a numbered word list, roll five dice (or one die five times), read off the five digit number, and take the matching word. Repeat until you have five or six words. It takes about three minutes, and the randomness lives outside any computer.
The software method: switch your password manager's generator from random characters to word mode, ask for five or six words, and take what it gives you. Good generators use the operating system's cryptographic randomness, which is genuinely unpredictable. If you are choosing a manager or wondering how the vault keeps generated secrets, how a password manager stores and unlocks your vault covers the mechanics.
The mistake is editing the result. Rerolling a word you dislike, dropping one that is hard to spell, or shuffling the order into something that reads nicely all shrink the space in ways an attacker can model. If a word is genuinely unusable, discard the whole phrase and generate a fresh one.
A few details. Separators such as hyphens or spaces are for readability and for awkward site rules, and add almost nothing to strength. Capitalizing the first letter adds about one bit, which is nothing worth counting. Bolting a digit on the end is fine when a form insists, but never let it replace a word.
Where passphrases belong and where they do not
A passphrase is the answer for secrets you must type from memory, on a keyboard, sometimes on a television remote or a games console. That list is short for most people:
- the master password for your password manager
- your device login or disk encryption password
- your main email account, the one that can reset everything else
- the passphrase on an encrypted backup drive
- the home wifi key you read out to visitors
Everything else should be a long random string that you never see and never type, generated and filled by software. There is no memory benefit to a passphrase on an account you sign into with autofill, and random characters pack more strength into the same length. That division also fixes the habit that does the real damage, which is using one password across many accounts.
Two things a passphrase does not do. It does not protect you if the site you used it on is breached and the attacker walks away with your plain text password, which is why uniqueness still matters. And it does not stop someone who already has the password from signing in, so put a second factor on the accounts that matter as well. If you have been recycling a phrase for years, run it through a check against known breach data before you trust it again.
Remembering it without taping it to the monitor
Random words are easier to memorize than random characters, but not free. The trick is spaced repetition in the first week: type the phrase from memory a few times the day you create it, then once or twice daily for a week. After that it lives in muscle memory.
For the first month, write it on paper and keep it where you keep your passport or your house deeds. That is not a security failure, it is a recovery plan: a master password has no reset link, and losing it can mean losing every credential in the vault. Once the phrase is solid, move the paper into a sealed envelope with your important documents. Tell whoever would need your accounts in an emergency that the envelope exists, and set up your recovery options and backup codes while you are thinking about it.
One popular shortcut defeats the whole thing: storing the master passphrase in your browser's saved password list, or in a note inside the vault it unlocks. The trade offs of leaving credentials to the browser are set out in the case for and against browser saved passwords.
The setup worth doing today
Pick the secret that protects the most: your password manager master password if you have one, otherwise your main email. Generate a fresh six word phrase with dice or a generator, change it, and start the week of practice. Then do a five word phrase for your computer login. Those two cover most of the risk you control from memory.
After that, stop memorizing. Let the manager generate 20 character random strings for everything else. For a feel for how much difference length makes, try a few made up examples in the password strength checker, and never type a real passphrase into any page that offers to score it.
Common questions
How many words does a passphrase need?
Five or six if the phrase guards something that could be attacked offline, such as a password manager vault, an encrypted disk or a backup drive. Four is enough for an ordinary account where the login page limits guessing. Each extra word multiplies the number of possible phrases by the size of the word list, so going from four to six words is not a small upgrade.
Can I use a line from a song I like?
No. Lyrics, film quotes, scripture and famous opening lines exist as plain text in enormous quantities, and password cracking tools ingest exactly that material. A line you can recall on demand is a line someone has already turned into a candidate list. The memorability that makes it appealing is what makes it guessable.
Does it matter if the words are separated by hyphens or spaces?
Barely. Separators mainly help you read the phrase back and satisfy sites that demand a non letter character. An attacker guessing word by word tries the common separators automatically. Use whatever the field accepts, and if spaces are rejected, hyphens or nothing at all are equally fine.
What happens if I forget my master passphrase?
In most password managers, nothing can be done. The vault is encrypted with a key derived from that phrase, so the provider cannot reset it or read your data. That is a security feature with a sharp edge. Write the phrase on paper for the first month, store it with your important documents, and print any emergency recovery kit the manager offers.