Understanding Passphrases


Learn what makes a passphrase secure, when to use one instead of a password, and how to create strong, memorable passphrases.


What is a passphrase?

A passphrase is a sequence of random words used as a password. Unlike traditional passwords that mix random characters (A7#kL2!xP9@), passphrases use complete words that are easier to remember and type.


Example:


Passphrases became popular after a famous 2007 comic by xkcd illustrated that a sequence of common words can be both more secure and more memorable than a short complex password.


Password vs Passphrase - Which should you use?


Feature Password Passphrase
Format Random characters (letters, numbers, symbols) Random words separated by spaces, hyphens, or CamelCase
Length Typically 8-16 characters Typically 20-50+ characters
Memorability Hard to remember, easy to forget Easier to remember (words create mental images)
Typing Prone to typos, especially symbols Easier to type correctly
Best for Password manager storage, accounts you rarely log into manually Master passwords, accounts you type frequently, device encryption
Entropy High if truly random, but humans are bad at random High when using 5+ random words

When to use a password:


When to use a passphrase:


Why are passphrases easier to remember?

The human brain is optimized for remembering stories, images, and concepts - not random sequences.


Cognitive science behind it:


Example comparison:

Try to memorize these for 10 seconds, then look away:


Password: Tr0ub4dor&3


Passphrase: correct-horse-battery-staple


Why are passphrases secure?

Passphrase security comes from word count and word pool size.


The mathematics:

Our word list contains 7,776 unique words. The number of possible combinations grows exponentially with each added word:


Word Count Possible Combinations Entropy (bits) Time to Crack
3 words 7,776³ = 470 billion ~39 bits A few hours
4 words 7,776⁴ = 3.7 trillion ~52 bits A few days
5 words 7,776⁵ = 28 trillion ~65 bits A few years
6 words 7,776⁶ = 225 trillion ~78 bits Hundreds of years
7 words 7,776⁷ = 1.7 quadrillion ~91 bits Thousands of years
8 words 7,776⁸ = 13 quadrillion ~104 bits Millions of years

Comparison to passwords:


Key insight: Length (in words) beats complexity. A 6-word passphrase is stronger than an 8-character password with symbols, and much easier to remember.


What makes a GOOD passphrase?

Characteristics of strong passphrases:


1. Random, unrelated words


2. Minimum 5-6 words


3. Unpredictable word choice


4. No personal information


5. Not a common phrase or quote


Pro tip: Use a passphrase generator (like ours) to ensure true randomness. Humans are terrible at being random - we unconsciously follow patterns.


What makes a BAD passphrase?

Common mistakes that weaken passphrases:


1. Common phrases or quotes


2. Song lyrics or movie lines


3. Personal information


4. Too short


5. Related words


6. Simple patterns


Real-world example: The passphrase correct-horse-battery-staple from the famous xkcd comic is now terrible because it's well-known and included in attacker dictionaries. Never use famous example passphrases!


Passphrase examples


Good passphrases (random, 6+ words):


Bad passphrases (common, short, or personal):


Separator comparison:

Same 5 words, different formats:


Format Example Pros Cons
Hyphen correct-horse-battery-staple Clear word boundaries, easy to type Slightly longer
Space correct horse battery staple Most readable, natural Some systems don't accept spaces
CamelCase CorrectHorseBatteryStaple Compact, no special chars Harder to read, case sensitivity matters
No separator correcthorsebatterystaple Shortest Word boundaries unclear, harder to remember

Our recommendation: Use hyphens for the best balance of readability, security, and compatibility.


← Back to Password Benchmark

Protected by Cloudflare