What a passphrase is
A passphrase is a password made of several random words, such as panoramic-nectar-precut-smith-banana-handclap. It is long, which makes it hard to guess, and it is made of real words, which makes it easy to type and possible to remember. The words have to be picked at random. A line from a song or a sentence you made up is far easier to guess than it looks.
Why a passphrase beats a short complex password
Length does more for a password than odd characters do. A password like Tr0ub4dor&3 looks strong, but people build such passwords in the same few ways, and guessing software knows those ways. Six random words are longer, have more possible combinations, and are easier to type on a phone.
The current US government guidance says the same. NIST’s digital identity guidelines, SP 800-63B revision 4, published in August 2025, state that “password length is a primary factor in characterizing password strength.” They tell services not to demand a mix of character types, to require at least 15 characters when a password is the only thing protecting an account, and to accept passwords of at least 64 characters so that passphrases fit.1
The Electronic Frontier Foundation, which publishes the word list this tool uses, suggests a six-word passphrase for most uses.2
How many words you need
Six words is a good choice for anything that matters: your password manager, your email, your computer login, an encrypted drive. Each word is one of 7,776, so each adds about 12.9 bits of entropy. One more word makes the passphrase 7,776 times harder to guess.
| Words | Entropy | Possible passphrases | Average time to guess |
|---|---|---|---|
| 4 | 51.7 bits | 3.7 × 1015 | 30 minutes |
| 5 | 64.6 bits | 2.8 × 1019 | 165 days |
| 6 | 77.5 bits | 2.2 × 1023 | 3,500 years |
| 7 | 90.5 bits | 1.7 × 1027 | 27 million years |
| 8 | 103.4 bits | 1.3 × 1031 | 212 billion years |
| 10 | 129.2 bits | 8.1 × 1038 | 1019 years |
The times assume an attacker who has stolen a scrambled copy of your passphrase and can test one trillion (1012) guesses every second, the rate Edward Snowden told a journalist to assume in 2013.3 On average the attacker finds it after trying half of the possibilities, and that is the figure shown. This is a harsh case. A website’s login page allows a few guesses, not a trillion a second, and services that store passwords with a slow hash cut the rate by many orders of magnitude. An attacker with more hardware goes faster, which is why the tool shows the math and not a promise.
Capital letters and the separator are fixed by your settings, so they add no entropy. A random digit added after one random word adds a few bits (5.9 bits on six words). They are there for sites that insist on a capital or a number.
How the words are picked
The classic method is diceware: roll five dice, read the five numbers as one of 7,776 entries in a word list, write the word down, and repeat. This tool does the same job with your browser’s cryptographic random number generator, the one used for encryption keys. Numbers that would make some words slightly more likely than others are thrown away and drawn again, so every word has exactly the same chance.
The password tab works the same way. Every character is drawn evenly from the kinds you chose. If a password comes out missing one of those kinds, the whole password is thrown away and a new one is drawn, which keeps every allowed password equally likely.
How to keep your passphrase
- Use a password manager. Let it hold a different random password for every account, and protect it with one passphrase that you remember.
- Memorize the few that open everything else. Your password manager, your computer login and your main email. Type a new passphrase a few times a day for the first week and it will stick.
- Write it on paper while you learn it. Keep the paper somewhere safe at home, not in a notes app, a photo or an email draft.
- Never reuse it. One passphrase, one place. A passphrase used on two sites is only as safe as the weaker site.
- Add a second step. Turn on two-factor authentication wherever it is offered.
Secria Mail uses the same idea
When you create a Secria Mail account you get a recovery phrase of 12 random words. It is your way back in if you forget your password. Your mailbox is stored with zero-access encryption, locked with a key made from your password on your device. Secria Mail is free to start.
Questions about passphrases
Is a passphrase better than a password?
A random passphrase of six words is stronger than the short, complex passwords most people make up, and it is easier to type and remember. A long random password from a generator can be just as strong or stronger, but it is hard to remember, so it belongs in a password manager. Use a passphrase for the few secrets you must remember and random passwords for everything else.
How many words should a passphrase have?
Six words from a 7,776-word list is a good default and is what the Electronic Frontier Foundation suggests for most uses. That is about 77.5 bits of entropy. Use seven or eight for something you expect to keep for many years, such as the passphrase for a password manager or an encrypted backup.
Is it safe to use an online passphrase generator?
It depends on where the passphrase is made. This generator runs in your browser: the word list is part of the page, the random numbers come from your own device, and nothing is sent, saved or logged. You can disconnect from the internet after the page loads and it still works. If you want no software involved at all, roll five dice per word and look the words up in the EFF list.
What is diceware?
Diceware is a way to make a passphrase with dice. You roll five dice, read the result as a five-digit number, and look up the matching word in a list of 7,776 words. Repeat for each word. Because dice are random and the list is public, the strength comes only from the number of words, which makes it easy to measure.
Should I add numbers and symbols to a passphrase?
Only if a site demands them. Fixed changes like a capital on every word add nothing an attacker has to guess. A random digit adds a few bits. One more word adds about 12.9 bits, far more than any of them.
How long does it take to crack a passphrase?
It depends on the number of words and the attacker’s speed. At one trillion guesses per second, a six-word passphrase from this list takes about 3,500 years to guess on average, five words take about 165 days and four words about 30 minutes. Against a login page that limits attempts, all of them last far longer.
Sources
- NIST, SP 800-63B-4, Digital identity guidelines: authentication and authenticator management, section 3.1.1.2 and appendix A (August 2025).
- Electronic Frontier Foundation, EFF dice-generated passphrases.
- Wired, These are the emails Snowden sent to first introduce his epic NSA leaks (October 2014): “Assume your adversary is capable of one trillion guesses per second.”