Passphrase vs password
Both are secrets you type to log in. The real question is how random they are and whether you have to remember them. Here are the numbers.
| Random passphrase (6 EFF words) | Random password (12 characters) | Typical human password | |
|---|---|---|---|
| Example | crust-velvet-oboe-snarl-dwelling-apron | q7#Vm!2xRt9k | Summer2024! |
| Entropy | 77.5 bits (exact) | ≈ 78.8 bits (95 printable characters) | very low: common pattern |
| Length | ≈ 45 characters | 12 characters | 11 characters |
| Memorable? | Yes, with a mental picture | Hard | Yes, and so is its pattern |
| Phone typing | Easy: letters and one symbol | Slow: keyboard switching | Easy |
| Best for | Secrets you type from memory | Everything a password manager fills | Nothing |
Bits per character vs bits per word
A random character drawn from the 95 printable ASCII symbols is worth log2(95) ≈ 6.57 bits. A random EFF word is worth 12.9 bits but averages about 7 letters. So per keystroke, random characters win. Per thing-you-have-to-remember, words win by a mile: six chunks instead of twelve arbitrary symbols. Human memory counts chunks, not characters.
The rule of thumb
- Memorise a passphrase for your password manager, your main email, your computer login and disk encryption.
- Let the manager generate random passwords for everything else, unique to each site.
- Add two-factor authentication, ideally a passkey or security key, wherever it's offered.
NIST's digital identity guidelines point the same way: favour length, drop composition rules and forced changes. See our NIST password guidelines summary. To feel the difference, try the entropy calculator.
Questions
Is a passphrase more secure than a password?
A random passphrase of five or six words is stronger than most passwords people actually use, and comparable to a random 10–12 character password while being far easier to remember. What matters is randomness and length, not the label.
When should I use a random password instead?
For every account your password manager can fill for you. A 20-character random string you never type is stronger than any passphrase you'd want to memorise. Save passphrases for the few secrets you have to type from memory.
Are passphrases harder to type?
They are longer but usually faster to type, because they are made of familiar words with no switching between letters, digits and symbols. That is especially true on phone keyboards.