Passphrases vs Passwords: Why Four Random Words Beat P@ssw0rd
For years the rules told us a good password looked like P@ssw0rd! — a mix of upper, lower, digits, and symbols. Those rules optimized for the wrong thing: they made passwords painful for humans to remember while barely slowing down the computers that guess them. The better model is a passphrase — several random words — and understanding why comes down to one idea: entropy.
Strength is entropy, not punctuation
The strength of a secret is how many guesses an attacker needs, and that is measured in bits of entropy — essentially, how large the space of equally-likely possibilities is. Crucially, entropy depends on how the secret was chosen, not how complicated it looks:
P@ssw0rd!looks complex but follows a predictable pattern (capital first,a→@,o→0, symbol at the end). Password-cracking tools try exactly these substitutions first, so its real entropy is low.- Four words chosen randomly from a large list —
correct-battery-harbor-mantle— has far more entropy because there is no shortcut: an attacker has to consider every combination of words.
The Password Strength checker estimates entropy in bits and an offline crack-time, which makes the gap concrete: the "complex" password often scores worse than the longer passphrase that is easier to type.
Why length wins
Every character (or word) you add multiplies the search space. That is why length beats complexity: extending a password does more for entropy than sprinkling in symbols. A long passphrase of common words can be both stronger and easier to remember than a short string of gibberish — the rare win-win in security. Modern guidance (including NIST SP 800-63B) reflects this: it favors length, drops mandatory periodic rotation, and drops forced complexity rules, because those rules pushed people toward predictable patterns and sticky notes.
The catch: "random" has to mean random
A passphrase is only strong if the words are chosen by something with real randomness, not by you. Humans pick memorable, related words ("summer beach vacation fun"), which collapses the entropy back down. Use a generator that draws from a large word list with cryptographic randomness — the Password Generator offers a passphrase mode that does exactly this, and generates strong random-character passwords too when a site's rules demand them.
Practical rules that actually help
- Long and unique per site. Length is your biggest lever; reuse is the biggest risk. A breach of one site should not unlock the others.
- Use a password manager. It makes "unique everywhere" effortless and removes the memorization problem entirely — you only remember one strong passphrase.
- Add a second factor. Even a strong password benefits from 2FA; a time-based code (see how TOTP works) blocks attackers who somehow get the password.
- When you must share a credential, hand it over encrypted with Secure Paste rather than pasting it into chat.
The takeaway
Stop optimizing passwords for how complicated they look and start optimizing for entropy — which mostly means length and genuine randomness. A handful of randomly chosen words beats P@ssw0rd! on both strength and memorability. Generate one with the Password Generator, sanity-check it with the Password Strength meter, and let a password manager carry the rest.
Sources
- NIST SP 800-63B (Digital Identity Guidelines) — https://pages.nist.gov/800-63-3/sp800-63b.html
- This article expands on original editorial guidance from Online Dev Tools.