PhraseForge knowledge library

What makes a passphrase strong in practice

Most discussions about passphrase strength start too late. They begin with separators, capitals, or minimum word counts, as if the visible finish were the main source of value. It is not. The first question is whether the secret was generated in a way an attacker can model cheaply. Everything else follows from that.

Start with origin

A passphrase chosen for what it means is already weaker than many users think, even before anyone counts the words. If the phrase reflects taste, memory, place, humour, politics, or some other personal logic, the attacker has been given structure. That structure may be broad rather than bespoke, but it still helps. Random selection removes most of that advantage. It does not make the secret perfect. It does move the attacker away from the human-authored cues that ranking systems exploit first.

Count matters, but count is not the whole argument

Users like fixed minimums because fixed minimums feel like certainty. Three words. Four words. Five words. The difficulty is that the same count can mean different things depending on the pool, the account, and the way the words were chosen. A longer phrase built from one human idea stretched outward may still be badly exposed. A shorter but genuinely random phrase may be better than it looks. While the mainstream advice that "more words are better" is broadly fair, it becomes too simplistic once it is treated as a complete answer.

I would argue the better formulation is that more independent choices usually help. That is why another random word often adds more than another ornament. The extra word changes the structure of the whole secret. The extra symbol often just signals that the user complied with a rule.

Pool quality sets the upper bound

A passphrase generator is also a curation system. It decides what can be selected, how wide the vocabulary really is, and whether some words or themes are quietly overrepresented. Large clean pools reduce hidden structure. Narrower pools can still work, but they push more importance onto word count and independence. The common mistake is to assume that any word list automatically confers rigour. It does not. A poor list simply systematises a narrow band of habits.

Reuse can erase a great deal of technical virtue

Password discourse still likes to separate "strength" from "reuse," as if one belongs to mathematics and the other to personal discipline. That separation is too neat. A passphrase that travels is not strong enough for any serious account model. The 2025 reporting on huge credential compilations only reinforced that point.[1] Attackers do not need novelty everywhere. They need enough overlap to keep replay profitable.

So yes, a strong passphrase is random, long enough, and drawn from a decent pool. It is also unique. Leave that out and the rest of the discussion becomes oddly decorative.

Selected references

Keep exploring PhraseForge

Return to the generator or continue through the article library.

Back to generator Browse all articles Research notes