Passkeys and Sign-In
Passphrase vs Password: Why Four Random Words Work So Well
Passphrase vs password: why four random words beat short complex passwords, what NIST now advises, and how to make a passphrase you'll actually remember.
Last updated October 4, 2026 · 8 min readA passphrase is a password made of several words, such as four unrelated words in a row. In a passphrase vs password matchup, four or more truly random words usually win. They're harder for computers to guess than a short password full of symbols, and much easier for people to remember.
The catch is that the words must be picked at random, not chosen because they mean something to you.
What is a passphrase?
A password is any secret you type to prove it's you. A passphrase is simply a longer password built from words instead of a jumble of characters. It's the idea behind the popular "four random words" password advice.
Compare these two:
- A typical "complex" password: Tr0ub4dor&3
- A passphrase: four unrelated words, such as copper lantern mitten oxygen
The first looks tough, but it follows a pattern lots of people use. They start with a real word, swap some letters for numbers, and add a symbol and a number at the end. Guessing programs know these habits and try them early.
It's also hard to remember. Was that a zero or the letter o? The passphrase is easy to picture and says nothing about you.
Don't copy that example, or any other passphrase examples you see online. Published ones can end up on attackers' guessing lists.
Passphrase vs password security: why length beats symbols
When a website is breached, attackers often get its passwords in scrambled form. They then run programs that can make millions or even billions of guesses per second. What slows them down is the number of possible combinations.
Security experts call this "entropy." You can think of it as how many guesses an attacker might need.
Here's what that looks like with a list of 7,776 words. That's the size used by Diceware, a well-known method for choosing words with dice.
- One random word: about 7,800 possibilities. A computer gets through that instantly.
- Four random words: about 3.7 quadrillion.
- Five random words: about 28 quintillion.
- Six random words: about 220 sextillion.
These numbers already assume attackers know your exact word list. Each extra word makes their job about 7,800 times bigger. Adding one more symbol to a short password helps far less, especially when it's the same exclamation point everyone else adds.
To be fair, a truly random 8-character password of letters, numbers, and symbols has about 6 quadrillion possibilities. That's roughly the same as four random words. But almost nobody can remember k7#Qm!2x, and the passwords people make up are rarely that random.
Four words you can picture are better than eight characters you'll end up writing on a sticky note.
What NIST's current guidance says
NIST (the National Institute of Standards and Technology) is the U.S. agency whose digital identity guidelines shape how many organizations handle sign-in. The latest version, NIST SP 800-63B, moves away from the password rules many of us grew up with.
In plain terms, it says:
- Length beats complexity. If a password is the only thing you need to sign in, it should be at least 15 characters. Sites shouldn't force you to mix capitals, numbers, and symbols, because those rules push people toward predictable tricks.
- Long passphrases should fit. Sites should allow passwords up to at least 64 characters, accept spaces, and let you paste from a password manager.
- No changes just because time passed. Sites should ask for a new password when there's evidence it was exposed, not on a fixed schedule.
- Known-bad passwords get blocked. Sites should reject passwords that are common or that showed up in earlier breaches.
How long should a password be?
If you have to remember it, use at least four random words. That usually comes to 20 or more characters. If your password manager creates and remembers it for you, aim for 16 or more random characters.
Both meet the 15-character minimum NIST sets for passwords used on their own.
How to make a passphrase you'll actually remember
You don't need to be clever. You need randomness and a little practice.
- Get random words. For each word, roll five dice and look up the five-digit result in a Diceware-style list, like the Electronic Frontier Foundation's free long word list. Or use the generator in a password manager you trust.
- Use at least four words. Five or six give you extra protection for your most important accounts.
- Picture a scene. Turn the words into a silly image, like a copper lantern wearing a mitten and gasping for oxygen. Odd images stick.
- Practice it. Type it a few times on day one, again the next day, and again a week later.
- Use it in one place only. If you reuse a passphrase and one site leaks it, every account that uses it is exposed.
If a site demands a capital, number, or symbol, capitalize the first word and add a digit or symbol at the end. The random words do the real work.
It's fine to keep a paper copy somewhere private at home until you know the phrase by heart. Just don't stick it on your screen.
Why the words need to be random
Randomness is what makes a passphrase strong. Guessing programs don't just try letters one at a time. They start with real words, names, and famous phrases, so anything that means something to you, or to lots of people, gets guessed sooner.
These make weak passphrases:
- A song lyric, movie quote, or Bible verse. Famous lines are already on guessing lists.
- Your kids' names, your pet's name, your street, or your hometown. These are often easy to find on social media.
- A common saying, like "to be or not to be."
- A sentence that makes sense, like "my dog loves pizza."
- Words you picked by glancing around the room, like lamp, mug, and window.
If you get a word you can't spell, it's fine to roll again. Just don't keep swapping words until the phrase tells a story, because stories are easier to guess.
Where passphrases make the most sense
Use a passphrase when you have to remember the secret yourself and losing it would hurt. The best spots:
- Your password manager's master password. It protects everything else, so give it your most carefully made passphrase.
- Your computer login. You type it every day, often before your password manager is even open, so words beat a jumble of symbols.
- Your main email account. Email can reset almost every other account. If your email doesn't offer a passkey yet, use a passphrase and turn on two-step verification, which asks for a second check like a code from an authenticator app.
- Your home Wi-Fi. Guests have to type it, and four words are easier to read aloud than a string of symbols. Our Wi-Fi password ideas guide has more guest-friendly options.
A passphrase does have limits. Length can't protect it if you type it into a fake login page, or if a careless site stores it unscrambled and then leaks it. Passkeys avoid both problems.
A passkey is a newer way to sign in. You use Face ID, a fingerprint, or your device's screen lock instead of typing a secret. It only works on the real website, and the site never stores a secret that thieves could reuse.
When an account offers a passkey, it's often the easiest and safest choice. Our plain-English guide to passkeys shows how they work. If you're deciding what should unlock a password vault, see master password vs passkey.
Where a password manager should do the remembering
Nobody can memorize dozens of passphrases, and you shouldn't try. For most accounts, the best password is one you never have to remember. It's a long random password that a password manager creates, stores, and fills in for you.
Because every password is different, a leak at one website can't unlock the rest. That leaves you with a single passphrase to memorize: the one that opens your manager.
Pinzen is built around that idea. When you set up a vault, you create a master phrase, and Pinzen can suggest four random words for you.
Your phrase is processed on your own device with Argon2id, a method designed to make every guess slow and costly. It's then combined with an Account Secret, a long random code (256 bits) stored in your Recovery Kit file and on your trusted devices. Trusted devices are the phones and computers where you've set up your vault.
Neither the phrase nor the Account Secret is sent to us, and our servers store only encrypted data.
The tradeoff is that we can't see or reset your master phrase. If you forget it, your Recovery Kit or a trusted device can get you back in, because the Kit works as a complete spare key. Save the Kit during setup and keep it somewhere safe.
A trusted device also reopens your vault without the phrase, so you may not need to type it very often. Practice it now and then so you don't forget it.
See what happens if you forget your master password for recovery details, or read how our encryption works.
You can create a free vault in three steps. Create your master phrase, save the Recovery Kit, and turn on approval with Face ID, a fingerprint, or an authenticator app.
Frequently asked questions
Is a passphrase more secure than a password?
Usually, yes, when you compare a random passphrase with the kind of password most people make up. Four random words are far harder to guess than a real word with a few swapped characters and a symbol on the end. A long random password from a generator can be even stronger, but a passphrase has one big advantage: you can actually remember it.
How many words should a passphrase have?
Four random words is a good minimum for anything you need to memorize. For your most important accounts, like your main email, five or six words give extra protection. Each extra word multiplies the guessing work by thousands, as long as the words are picked at random rather than chosen by you.
Can I use spaces in a passphrase?
Often, yes. Many modern sites and apps accept spaces, and current NIST guidance says they should. If a site rejects them, put hyphens or periods between the words, or run the words together. The random words are what make it strong, so the separator matters far less.
What is an example of a strong passphrase?
Something like copper lantern mitten oxygen shows the style: four unrelated words chosen at random. Don't use that one, because published examples can end up on attackers' guessing lists. Make your own with dice and a word list, or use the four-word suggestion Pinzen offers when you set up a vault.