How Many Words Does Your Passphrase Actually Need? The Entropy Math, Worked Out
Everyone repeats "use more words" but nobody shows the numbers. Here they are, with the cracking math that convinced me to stop at six for most things and go to seven for the ones that matter.
I used to tell people to use a passphrase without being able to defend a specific number. "More is better" is true and useless. Then a friend asked me a fair question: is my four word passphrase actually safer than my old 12 character password with symbols? I did not know. So I sat down with the math, and now I do. Here is the full picture.
Each word is worth about 12.9 bits
The EFF Diceware long wordlist has 7,776 words. If a word is chosen uniformly at random, the number of possibilities doubles with every word, and each word contributes log2(7,776), which is roughly 12.9 bits of entropy. Entropy is just a count of how many guesses an attacker needs on average: n bits means about 2^(n-1) guesses.
So a six word passphrase has 6 times 12.9 = 77.5 bits of entropy. That means an attacker needs roughly 2^77.5, about 2.1 x 10^23, guesses on average to crack it. For comparison, a 12 character password drawn randomly from 94 printable characters gives log2(94^12) = about 78.7 bits. They are nearly identical in strength. The difference is that you can actually remember and type six words.
What the numbers mean against real hardware
This is where it gets concrete. Suppose an attacker steals a password database and can try one trillion guesses per second. That is an aggressive but realistic number for a well funded attacker with a GPU cluster in 2026, per analyses of offline attack rates.
- 4 words (51.7 bits): about 2^51.7 guesses = 3.7 x 10^15. At a trillion guesses per second, that falls in roughly 62 minutes. Fine for a throwaway account. Not fine for your email.
- 5 words (64.6 bits): about 2^64.6 guesses = 2.6 x 10^19. At a trillion per second, that is about 300 days. Respectable, and probably fine for ordinary accounts, but the margin is thinner than I like.
- 6 words (77.5 bits): about 2^77.5 guesses = 2.1 x 10^23. At a trillion per second, that is roughly 6.6 million years. This is the line I recommend. Six words is the sweet spot.
- 7 words (90.4 bits): about 8.3 x 10^7 years at a trillion guesses per second. This is what I use for my password manager master secret and disk encryption.
- 8 words (103.4 bits): beyond this you are protecting against attackers with physics breaking computers. Useful only for the most critical secrets.
Notice the jump from five to six words: it multiplies the attacker's work by about 8,000. Each extra word multiplies the search space by 7,776. That is the exponential part of "more words is better," and it is why going from four to six matters far more than any symbol substitution ever could.
Why your four word passphrase beats a clever 8 character password
An 8 character password from a 62 character alphanumeric set gives about 47.6 bits. At a trillion guesses per second, that falls in under 19 minutes. And real 8 character passwords are far weaker than the theoretical number, because people pick patterns: a word, a digit, a symbol at the end. NIST's own analysis of breached databases found that users respond to complexity rules with predictable substitutions like "P@ssw0rd," which provide almost no real security while making the password miserable to type.
NIST SP 800-63B dropped mandatory composition rules for exactly this reason and now requires a minimum of 8 characters with support for at least 64, accepting all printable ASCII, spaces, and Unicode. The modern guidance is length first. A four word diceware passphrase at 51.7 bits already beats a random 8 character password, and it is dramatically easier to get right in practice because the randomness is doing the work, not your memory.
The catch: the words must actually be random
All of this math assumes each word was chosen by a random process. Human chosen words destroy the math. If you pick "sunset beach coffee happy," an attacker does not need to search 7,776 words; they search the few thousand words people actually pick, in orders people actually use. Analyses consistently show that human word selection introduces biases that collapse effective entropy compared to the theoretical number.
This is the whole reason diceware exists: roll physical dice, or use a generator built on a cryptographic random source like crypto.getRandomValues(), and the math holds. It will feel wrong. "Correct horse battery staple" feels less secure than "Tr0ub4dor&3" because it looks simple. The numbers say the opposite.
My actual recommendations
After doing this math, here is what I tell people, and what I do myself:
- Low value accounts (forums, newsletters): 4 to 5 words is honest protection.
- Important logins (email, banking, anything tied to your identity): 6 words minimum. This is the line.
- Secrets that unlock other secrets (password manager master password, disk encryption, crypto wallets): 7 words. The extra word costs you one more word to memorize and buys you a factor of 7,776 in attacker work.
And one more thing the math taught me: adding a word beats complicating words, every time. If a site demands a digit, append one at the end rather than mangling a word. You keep almost all the strength and all of the memorability.
Frequently asked questions
Is 4 words enough for a passphrase?
For low stakes accounts, 4 words (51.7 bits) is reasonable. For anything important, I would not stop at 4. The jump to 6 words multiplies attacker effort by roughly 60 million. Memorize two more words and sleep better.
How does passphrase entropy compare to a 16 character random password?
A 16 character password from 94 printable characters gives about 104.8 bits, which is slightly stronger than an 8 word passphrase (103.4 bits) and clearly stronger than 6 words (77.5 bits). But you cannot memorize a 16 character random string, so in practice it lives in a password manager, which is exactly where random strings belong.
Do separators between words add security?
Barely. A space, dash, or nothing between words adds at most a couple of bits if the attacker does not know your separator habit, and zero if they do. Choose the separator for typability, not security. If anything, pick what the site accepts and move on.