Back to the tool

How Many Words Does Your Passphrase Actually Need? The Entropy Math, Worked Out

Everyone repeats "use more words" but nobody shows the numbers. Here they are, with the cracking math that convinced me to stop at six for most things and go to seven for the ones that matter.

I used to tell people to use a passphrase without being able to defend a specific number. "More is better" is true and useless. Then a friend asked me a fair question: is my four word passphrase actually safer than my old 12 character password with symbols? I did not know. So I sat down with the math, and now I do. Here is the full picture.

Each word is worth about 12.9 bits

The EFF Diceware long wordlist has 7,776 words. If a word is chosen uniformly at random, the number of possibilities doubles with every word, and each word contributes log2(7,776), which is roughly 12.9 bits of entropy. Entropy is just a count of how many guesses an attacker needs on average: n bits means about 2^(n-1) guesses.

So a six word passphrase has 6 times 12.9 = 77.5 bits of entropy. That means an attacker needs roughly 2^77.5, about 2.1 x 10^23, guesses on average to crack it. For comparison, a 12 character password drawn randomly from 94 printable characters gives log2(94^12) = about 78.7 bits. They are nearly identical in strength. The difference is that you can actually remember and type six words.

What the numbers mean against real hardware

This is where it gets concrete. Suppose an attacker steals a password database and can try one trillion guesses per second. That is an aggressive but realistic number for a well funded attacker with a GPU cluster in 2026, per analyses of offline attack rates.

Notice the jump from five to six words: it multiplies the attacker's work by about 8,000. Each extra word multiplies the search space by 7,776. That is the exponential part of "more words is better," and it is why going from four to six matters far more than any symbol substitution ever could.

Why your four word passphrase beats a clever 8 character password

An 8 character password from a 62 character alphanumeric set gives about 47.6 bits. At a trillion guesses per second, that falls in under 19 minutes. And real 8 character passwords are far weaker than the theoretical number, because people pick patterns: a word, a digit, a symbol at the end. NIST's own analysis of breached databases found that users respond to complexity rules with predictable substitutions like "P@ssw0rd," which provide almost no real security while making the password miserable to type.

NIST SP 800-63B dropped mandatory composition rules for exactly this reason and now requires a minimum of 8 characters with support for at least 64, accepting all printable ASCII, spaces, and Unicode. The modern guidance is length first. A four word diceware passphrase at 51.7 bits already beats a random 8 character password, and it is dramatically easier to get right in practice because the randomness is doing the work, not your memory.

The catch: the words must actually be random

All of this math assumes each word was chosen by a random process. Human chosen words destroy the math. If you pick "sunset beach coffee happy," an attacker does not need to search 7,776 words; they search the few thousand words people actually pick, in orders people actually use. Analyses consistently show that human word selection introduces biases that collapse effective entropy compared to the theoretical number.

This is the whole reason diceware exists: roll physical dice, or use a generator built on a cryptographic random source like crypto.getRandomValues(), and the math holds. It will feel wrong. "Correct horse battery staple" feels less secure than "Tr0ub4dor&3" because it looks simple. The numbers say the opposite.

My actual recommendations

After doing this math, here is what I tell people, and what I do myself:

And one more thing the math taught me: adding a word beats complicating words, every time. If a site demands a digit, append one at the end rather than mangling a word. You keep almost all the strength and all of the memorability.

Frequently asked questions

Is 4 words enough for a passphrase?

For low stakes accounts, 4 words (51.7 bits) is reasonable. For anything important, I would not stop at 4. The jump to 6 words multiplies attacker effort by roughly 60 million. Memorize two more words and sleep better.

How does passphrase entropy compare to a 16 character random password?

A 16 character password from 94 printable characters gives about 104.8 bits, which is slightly stronger than an 8 word passphrase (103.4 bits) and clearly stronger than 6 words (77.5 bits). But you cannot memorize a 16 character random string, so in practice it lives in a password manager, which is exactly where random strings belong.

Do separators between words add security?

Barely. A space, dash, or nothing between words adds at most a couple of bits if the attacker does not know your separator habit, and zero if they do. Choose the separator for typability, not security. If anything, pick what the site accepts and move on.

Try the tool

Everything above is easier to believe once you have seen it in action. Generate a passphrase now on the homepage. It runs entirely in your browser and takes about three seconds.

Keep reading

The One Passphrase Setup: Why Your Password Manager Deserves a Great Master Secret