Use a long random password when a password manager can store and autofill it. Use a random passphrase when you must type the secret yourself or remember it well enough to unlock a password manager, computer, or encrypted drive. Either format can be strong when every character or word is selected randomly and the result is used only once.
Quick answer: Machine-handled login → random password. Human-entered master secret → random passphrase. A familiar sentence, quotation, or modified personal phrase is neither.
Passphrase vs. password at a glance
| Question | Random password | Random passphrase |
|---|---|---|
| What is selected? | Individual characters | Independent words |
| Best handled by | Password manager or autofill | A person who must type it |
| Typical shape | Compact and dense | Longer and easier to read |
| Main strength control | Character set and length | Word-list size and word count |
| Good use cases | Website accounts and generated credentials | Manager master password, device login, encrypted drive |
| Main mistake | Reusing one generated password | Choosing a quotation or meaningful sentence |
This comparison applies to randomly generated credentials. A human-made password such as a name plus a year and a human-made passphrase such as a lyric are predictable even when they look long.
What is a random password?
A random password selects each character from an allowed set such as uppercase letters, lowercase letters, digits, and symbols. Because a large character pool is used at every position, it can provide substantial guessing resistance in a relatively short string.
That density makes random passwords ideal for ordinary online accounts. They do not need to be memorable when a password manager creates, stores, and fills them. Use the site’s maximum supported length when it is restrictive; otherwise, generate a strong password of about 20 characters as a practical default.
What is a random passphrase?
A random passphrase selects complete words independently from a sufficiently large list. Separators and capitalization make the result easier to scan, but the unpredictability comes mainly from the number of possible words and the number selected.
The words must not form a quotation, sentence, theme, or personal story. Six unrelated words selected by a secure generator are fundamentally different from six words you invented because they sound natural together. Use the random passphrase generator when a credential must be entered by hand.
Which is stronger: a passphrase or a password?
Compare the word list, not just the number of words
The two word-based tools on this site now use the 7,776-word EFF Long Wordlist. With independent uniform selection, the word contribution is word count × log2(7776):
| Words | Approximate word entropy | Practical difference |
|---|---|---|
| 4 | 51.7 bits | Shorter to type, substantially smaller search space |
| 6 | 77.5 bits | EFF’s recommended starting point for a list of this size |
| 8 | 103.4 bits | More guessing resistance, but a longer credential |
An optional uniformly random two-digit number from 10 to 99 adds about 6.5 bits. A fixed hyphen or capitalizing every word adds no randomness. These figures describe the generation process, not a guaranteed time to crack an account.
Use the memorable password generator for a readable format with an optional number, or the passphrase generator for a six-word starting point. Both share the same word list; their defaults and intended typing workflow differ. Check that your service accepts the entire result.
Source and method: EFF’s dice-generated passphrase guidance. This website uses browser cryptographic randomness instead of physical dice.
Neither format is automatically stronger. Strength depends on the size of the possible search space and whether the choices are genuinely random. A long random password can exceed the strength of a shorter passphrase; a sufficiently long random passphrase can exceed a short character password.
Length alone is not proof of randomness. Attackers test leaked passwords, keyboard patterns, dates, substitutions, quotations, and common word combinations before attempting every possible value. This is why correct-looking-personal-phrase is a poor model even though it occupies many characters.
For generated credentials, compare the entropy estimate rather than character count alone. For human-created credentials, assume the estimate is lower than a simple length formula suggests because human choices are not independent.
Use a random password for ordinary accounts
Choose a random password when software will do the remembering and typing. This is the normal choice for email, shopping, banking, social media, work applications, and other websites.
- Generate a unique result for every account.
- Store it immediately in a reputable password manager.
- Use autofill instead of repeatedly copying through the clipboard.
- Enable a passkey or phishing-resistant MFA when the service supports it.
- Never simplify a generated result by adding a familiar pattern.
Current NIST digital identity guidance supports password managers and paste functionality and emphasizes screening new passwords against commonly used or compromised values. Random, unique generation avoids many of the patterns such screening is intended to catch.
Use a random passphrase when you must type it
Choose a passphrase for the small number of important secrets that cannot always be autofilled. Common examples include a password manager’s master credential, a computer login, an encrypted drive, or a backup that must be opened during recovery.
Start with six independently selected words unless the product gives more specific instructions. Add another random word for more security margin. Changing a separator or capitalizing words can improve compatibility or readability, but it should not replace adequate word count.
Before adopting one, test that you can enter it accurately on the relevant keyboard and confirm that the service accepts its full length. Store the recovery key or other recovery material separately and securely; memorization should never be the only recovery plan.
What should you use for Wi-Fi?
A random character password is usually the practical choice for a WPA2 or WPA3 home network. A 20–24 character result is compact enough to enter on TVs, printers, and consoles, and built-in QR or proximity sharing can reduce manual typing. The Wi-Fi password generator uses a device-friendly character set for this purpose.
A random passphrase can also work when the router accepts it, but several long words may be awkward on small device keyboards. Whichever format you choose, do not reuse the router administrator password as the Wi-Fi network password.
Common mistakes with both formats
- Reusing the result: One breach can expose every account that shares it.
- Editing in personal details: Names, dates, addresses, teams, and pets reduce unpredictability.
- Using a famous phrase: Quotations and lyrics are already in attackers’ dictionaries.
- Trusting visual complexity: Punctuation does not rescue a short or patterned credential.
- Sending it through ordinary chat or email: The delivery copy can persist long after use.
- Skipping recovery planning: A strong secret is not helpful if the only authorized user becomes permanently locked out.
A 30-second decision rule
Ask one question: who will enter this credential most of the time?
If a password manager or application will fill it, choose a unique random password. If you personally need to type it, choose a random passphrase with enough independent words. If the service offers a passkey, consider using it for routine sign-in while keeping the recovery method protected.
Do not convert an existing reused password into a passphrase by extending it. Generate a completely new value, save it, verify that sign-in works, and then remove the old credential from places where it was reused.