Passphrase vs random password
Is a short passphrase “better” than a long random password? It depends what you mean by better. Memorability and search-space size are different jobs. This guide compares 4, 5, and 6-word passphrases with one 16-character random password using the same entropy math the password generator uses, with the tool’s real EFF word-list size and character-set size.
Fake samples (do not use them)
- 4 words:
correct-battery-staple-quiet - 5 words:
correct-battery-staple-quiet-zebra - 6 words:
correct-battery-staple-quiet-zebra-abacus - Random password (exactly 16 characters):
Xh4!mK9pQ2$vL7nR
All of those strings are invented for the article. Every passphrase word appears in the generator’s list. Regenerate in the tool if you need a real secret.
How the bits are counted here
The passphrase mode draws from the EFF large wordlist of 7,776 words. Entropy bits ≈ word count × log₂(7,776):
| Words | Bits (approx.) |
|---|---|
| 4 | 51.7 |
| 5 | 64.6 |
| 6 | 77.5 |
The tool defaults to 5 words and lets you slide from 3 to 8.
For a random password with uppercase, lowercase, digits, and symbols enabled (ambiguous characters still included), the generator’s character set has 85 symbols. Entropy bits ≈ length × log₂(charset size):
- 16 × log₂(85) ≈ 102.6 bits
Under that model, the 16-character random sample still sits in a larger search space than a 6-word EFF passphrase, while a 5-word phrase lands around the mid-60s in bits. Lengthening the passphrase raises its bits; shrinking the random password or its charset lowers its bits.
Generation uses your browser’s secure random number generator, not a weak pseudo-random shortcut.
What NIST SP 800-63B says to services
These points are requirements aimed at verifiers and credential service providers, not personal advice for individuals choosing a password. The source is NIST SP 800-63B (revision 4):
- A password may also be called a passphrase.
- A password used as the only authentication factor must be at least 15 characters.
- Services should allow at least 64 characters.
- Services must not impose composition rules such as mixing character types.
- Services must not force periodic password changes (they must still force a change if the authenticator is compromised).
The practical takeaway for length and mix: length matters more than character mix. That is why a longer passphrase can be a reasonable choice even when it uses ordinary words, and why a dense 16-character random string still scores higher bits under this site’s charset model.
Also remember: a password written on a whiteboard, or baked into a Wi-Fi QR code, is no longer only “in your head.” If you are printing guest Wi-Fi access, read how to make a Wi-Fi QR code.
Practical takeaway
- Use the password tab when a site wants a dense random string and you will store it in a manager.
- Use the passphrase tab when you need something easier to type from memory, and raise the word count until the entropy reading looks acceptable for that account.
- Never paste the fake samples above into a real account.
Why the bit gap shrinks as you add words
Each EFF word contributes about 12.92 bits (log₂ of 7,776). Four independent draws give about 51.7 bits; six draws give about 77.5. That is still below the sample 16-character password’s ~102.6 bits with an 85-symbol charset.
If you turn on “exclude ambiguous characters,” the password charset shrinks and password entropy falls for the same length. The article’s 85-symbol figure assumes that toggle is off, matching the worked sample’s character mix.
Wordlist credit
Passphrase words come from the Electronic Frontier Foundation’s large wordlist, licensed under Creative Commons Attribution 3.0 United States (CC BY 3.0 US). The EFF does not endorse Numbrixiya.
Generate your own
Open the generator, switch to the passphrase tab (default 5 words), and compare entropy as you change length or word count. Copy only what you just created.
Frequently asked questions
Are the sample passwords real secrets?
No. The hyphenated samples and Xh4!mK9pQ2$vL7nR are fake examples only. Generate fresh values in the tool and never reuse published samples.
Does a higher bit count guarantee safety?
No. Entropy estimates how large the search space is under the stated model. Phishing, reuse, and device malware sit outside that number.
Can I change word count or character sets?
Yes. The passphrase tab defaults to 5 words and allows 3 to 8. The password tab has length and character-set toggles.
Does generation leave my browser?
Generation and copy run in your browser with your browser’s secure random number generator. The samples in this article were written by hand for illustration.
Which word list does the passphrase mode use?
The EFF large wordlist (7,776 words), licensed CC BY 3.0 US. Attribution appears under the passphrase controls.
Related articles
Generators
How to make a Wi-Fi QR code
Make a guest Wi-Fi QR with the generator’s Wi-Fi tab. Demo: Guest-Cafe. Anyone who scans can read the password.