Password Generatorโ†’Specialized Version
๐Ÿ”‘

Memorable Password Generator

Generate memorable random-word passphrases

StrengthWeak ยท 46 bits

At a trillion guesses per second โ€” an offline attack against a fast hash โ€” exhausting this keyspace takes 32 seconds. Entropy assumes the attacker knows the 200-word list and the format; secrecy of the method buys you nothing.

  • Tempest-River-Ribbon-Ginger-Oxide-Lantern-67
  • Falcon-Citrus-Citrus-Poplar-Dolphin-Bobcat-97
  • Bison-Teakwood-Cedar-Summit-Sequoia-Lichen-25

Generated locally with crypto.getRandomValues and never transmitted. Even so, a password manager that generates in-process is a better habit than any web page, this one included.

Words, Not Characters

A passphrase made of randomly chosen words is easier to remember and โ€” at a sensible word count โ€” stronger than the short mixed-character password most people actually use.

The arithmetic is straightforward. Entropy comes from the size of the word list and the number of words drawn, not from how the result looks:

WordsList of 2,048List of 7,776 (Diceware)
333 bits39 bits
444 bits52 bits
555 bits65 bits
666 bits77 bits
777 bits90 bits
Four words is the widely-cited minimum and is genuinely marginal against a well-resourced attacker. Five or six is where a passphrase becomes comfortable.

The Words Must Be Chosen Randomly

This is where passphrases usually fail. A phrase *you* pick is not random: it comes from song lyrics, film titles, your own vocabulary and your own associations, all of which an attacker can model. "correct horse battery staple" is famous precisely because it was generated, not chosen.

The generator above draws each word independently from the browser's cryptographic random source. If a phrase looks meaningful, that is coincidence โ€” regenerate only if you dislike a word, never because it "seems too easy".

Where Passphrases Belong

  • Your password manager's master password. You type it daily and it must be memorable.
  • Full-disk encryption. Same reason.
  • SSH key passphrases. Typed often enough that a random string becomes painful.
  • Device unlock codes on anything without biometrics.
For everything else, a password manager stores a long random string and you never see it โ€” memorability buys you nothing there.

Padding Rules Make It Worse

Adding a digit and a symbol to satisfy a policy adds a handful of bits and destroys the memorability that was the point. If a site demands them, append them in a fixed position and count them as zero entropy, because that is roughly what they are worth against anyone who knows the convention.

Length Limits Are the Real Obstacle

A six-word passphrase is 35โ€“45 characters and some systems silently truncate at 16 or 20. When a passphrase is accepted at signup and rejected at login, truncation on one side and not the other is usually the cause.

Where Passwords Actually Leak

CauseShare of breachesMitigation
Reuse after another site's breachLargest single causeA unique password per site
PhishingLargeA password manager (it will not autofill on the wrong domain)
Weak or guessableModerateLength and real randomness
Server-side breachModerateNot yours to control; 2FA limits the damage
Notice that three of the four are unaffected by how complex an individual password is. Reuse is the dominant risk, and the only fix is a manager.

Storing Them, If You Are the Server

``javascript // Argon2id is the current recommendation const hash = await argon2.hash(password, { type: argon2.argon2id, memoryCost: 19456, // 19 MiB timeCost: 2, parallelism: 1, }); `

Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per password and generated by the library. Peppering โ€” a secret added outside the database โ€” helps only if the pepper lives somewhere the database dump does not.

Rules Worth Dropping

NIST SP 800-63B now advises against several long-standing practices:

  • Forced periodic rotation. It produces Password1, Password2` and nothing else.
  • Composition rules. They shrink the search space by making the pattern predictable.
  • Password hints and security questions. Both are usually easier to guess than the
password.
  • Truncating length. Accept at least 64 characters; a passphrase should fit.
Check candidates against a breached-password list instead. That single control removes more risk than every composition rule combined.

Frequently Asked Questions

How many words does a passphrase need?

Five or six drawn from a large list. Four words from a 2,048-word list is 44 bits, which is within reach of a determined offline attack; six words is 66 bits and is not. Use more words rather than adding symbols.

Can I pick the words myself?

No โ€” that is the one thing that breaks a passphrase. Human-chosen words come from a much smaller effective space than the word list suggests, because they cluster around common vocabulary, song lyrics and personal associations. Every word must be drawn randomly.

Is a passphrase better than a random password?

Not stronger per character, but stronger in practice for anything you must memorise: people choose weak short passwords and strong long passphrases. For credentials your password manager types for you, a 20-character random string is simpler and just as good.

Related Tools

Explore other tools you might find useful:

More Password Generator tools

You might also need