Password Generator→Specialized Version
🔑

Passphrase Generator

Generate memorable passphrases

StrengthVery weak · 31 bits

At a trillion guesses per second — an offline attack against a fast hash — exhausting this keyspace takes instantly. Entropy assumes the attacker knows the 200-word list and the format; secrecy of the method buys you nothing.

  • Umbrella-Ginger-Flint-Galaxy-65
  • Shelter-Emerald-Windmill-Heron-23
  • Dune-Ripple-Thistle-Cottage-17
  • Pollen-Geyser-Reef-Marble-29
  • Canyon-Quartz-Lichen-Warbler-02

Generated locally with crypto.getRandomValues and never transmitted. Even so, a password manager that generates in-process is a better habit than any web page, this one included.

Why Passphrases

A passphrase trades character density for memorability. velvet-harbor-quartz-lantern is 28 characters you can actually type on a TV remote, and its strength comes from the random *selection* of words, not from the words being obscure.

WordsEntropy (7,776-word list)Comparable to
339 bits7 random characters
452 bits9 random characters
565 bits11 random characters
678 bits13 random characters
790 bits15 random characters
Four words is the widely quoted minimum; six is the sensible floor for a master password or a disk encryption key.

The Randomness Has to Be Real

Choosing words yourself destroys the entropy. Human-chosen "random" words cluster hard around common nouns, and a phrase that means something to you is in a much smaller space than the word list suggests. Roll dice, or let a CSPRNG choose.

Assume the attacker knows the word list, the separator and the word count. Security comes from the number of possible selections, never from the method being secret.

Where Passphrases Beat Passwords

  • Master passwords — you type it daily and can never look it up.
  • Disk encryption — often typed before a password manager is available.
  • SSH key passphrases — same problem.
  • Device unlock and recovery codes — typed on the worst possible keyboards.
Everywhere else, a long random string is better, because a manager types it for you and length costs nothing.

Do Not "Improve" It

Capitalising the first letter, appending !, or swapping o for 0 adds a bit or two and makes the phrase harder to type. Add another word instead — that is worth 13 bits.

Where Passwords Actually Leak

CauseShare of breachesMitigation
Reuse after another site's breachLargest single causeA unique password per site
PhishingLargeA password manager (it will not autofill on the wrong domain)
Weak or guessableModerateLength and real randomness
Server-side breachModerateNot yours to control; 2FA limits the damage
Notice that three of the four are unaffected by how complex an individual password is. Reuse is the dominant risk, and the only fix is a manager.

Storing Them, If You Are the Server

``javascript // Argon2id is the current recommendation const hash = await argon2.hash(password, { type: argon2.argon2id, memoryCost: 19456, // 19 MiB timeCost: 2, parallelism: 1, }); `

Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per password and generated by the library. Peppering — a secret added outside the database — helps only if the pepper lives somewhere the database dump does not.

Rules Worth Dropping

NIST SP 800-63B now advises against several long-standing practices:

  • Forced periodic rotation. It produces Password1, Password2` and nothing else.
  • Composition rules. They shrink the search space by making the pattern predictable.
  • Password hints and security questions. Both are usually easier to guess than the
password.
  • Truncating length. Accept at least 64 characters; a passphrase should fit.
Check candidates against a breached-password list instead. That single control removes more risk than every composition rule combined.

Frequently Asked Questions

How many words do I need?

Four for a general-purpose passphrase (52 bits), six or more for a master password or disk encryption key (78+ bits). Each word added is worth about 13 bits.

Are passphrases actually easier to remember?

Yes, and by a wide margin — recall of four concrete nouns beats recall of a 12-character random string for almost everyone. That matters because a password you cannot remember gets written down or reset weekly.

Does it matter which separator I use?

Barely, for security — it adds a couple of bits at most. Hyphens are the practical choice because some systems reject spaces in passwords.

Related Tools

Explore other tools you might find useful:

More Password Generator tools

You might also need