CYBER WELFARE

Protect your Digital Privacy

The Power of Passphrases: How to Create a Passphrase You Will Remember

Additional resource for the lesson “The Power of Passphrases: How to Create One You Will Remember” — Online Security course

A passphrase is a handful of unrelated words used in place of a password. It is much longer than anything you would invent on the spot, considerably harder to guess, and — unlike a string of symbols — you can actually remember it. This resource shows how to create a passphrase and where it belongs among your accounts.

A. Why this matters

A passphrase is the practical answer to a problem almost everyone has: the passwords that are strong enough are impossible to remember, and the ones you can remember are not strong enough. Instead of a short cryptic string, you use a sequence of unrelated words. The result is much longer, far more resistant to automated guessing, and genuinely memorable.

For individuals and organizations alike, moving to passphrases makes life harder for attackers without making it harder for people — which is why the advice tends to stick.

The key idea: length is what defeats automated guessing. Four or five random words get you past sixteen characters without any effort at all.

B. Key concepts

Six ideas, each with what it changes for you.

Passphrase

A sequence of at least four to six words, ideally random and unrelated to each other. Its strength comes from length; its usability comes from the fact that words are easier to hold in mind than characters.

Why it matters to you: It lets you have a credential that is both strong and rememberable — which is precisely the trade-off that usually pushes people towards weak passwords.

Randomness of the words

The words should be genuinely unconnected: not a famous phrase, a song lyric, a proverb or a sentence that makes sense.

Why it matters to you: Attackers use dictionaries, quotation lists and language models that are very good at predicting the next plausible word. Nonsense defeats prediction; a memorable quotation does not.

Length as the main factor

A passphrase of several words easily passes the 16 characters recommended by R3, and current standards point the same way: in its 2025 revision of SP 800-63B, NIST set a 15-character minimum where a password is the only protection on an account, and shifted the emphasis from complexity to length.

Why it matters to you: You get above the threshold without contortions — and without the sticky note that usually follows a complicated password.

A little added complexity

Slipping in a number or a symbol, between words or at the end, satisfies services that still demand mixed character types.

Why it matters to you: It adds a small amount of strength and a lot of compatibility, at almost no cost to memorability.

Password manager plus passphrase

The passphrase becomes the master password of your password manager; the manager then generates unique, random passwords for everything else.

Why it matters to you: You remember exactly one credential. Every other account gets something long and random that you never need to see.

Passphrase plus MFA

A strong passphrase combined with multi-factor authentication — an authenticator app or a hardware key.

Why it matters to you: Two independent barriers. Even if the passphrase were somehow obtained, the account would stay closed. Where a service offers passkeys, they achieve the same end with even less to remember.

C. A practical example: Sara changes one account

Sara has used the same basic password for years: Sara!2019. It opens her email, her social accounts and an old shopping site she barely uses.

The shopping site is breached and its credentials circulate online. An attacker tries the same combination on her email address, and it works. From there:

  • The passwords on her social accounts are reset.
  • Personal messages and documents become readable.

After the lesson

Sara chooses a new passphrase for her email:

apple-storm-window-7-train

  • She learns it by heart — four words and a number, repeated a few times over a day.
  • She stores it in a password manager, which now generates a different password for every other account.
  • She turns on MFA for her email.

Now, if another site is breached, that passphrase is not in use anywhere else — and getting into her email would still require the second factor. The change took her one evening.

D. Try it yourself: build your first passphrase

Four steps, about five minutes. Do it with the account you care about most in mind.

Step 1 — Choose six words

  • Write down six words that have nothing to do with you and do not form a sentence.
  • Look around the room if it helps: wall, tea, lamp, snow, harbour, backpack.
  • Avoid names of people you know, places you have lived, and anything a person browsing your social profiles could guess.

Step 2 — Join them in your own way

  • Use separators, or none at all, and vary the capitalisation:
  • wallTea-lamp_snowHarbourBackpack

Step 3 — Add a little seasoning

  • Slip in a number and a symbol, so the phrase also satisfies services with character requirements:
  • wallTea-lamp_snow7HarbourBackpack!

Step 4 — Run the checklist

  • Is it at least 16 characters long? (R3)
  • Does it mix upper and lower case, at least one number and one symbol?
  • Is it free of personal details and of any famous phrase?
  • Could you type it from memory tomorrow morning?

Do not use any of the examples on this page as your own passphrase. Once an example is published, it is no longer random.

Then commit: use a passphrase built this way for one critical account — your primary or work email, or online banking. One is the right number to start with.

E. Videos, articles and further resources

Independent and institutional sources, all available in English.

NCSC (UK) — Three random words, or #thinkrandom
The national cyber security authority’s explanation of why three random words beat conventional complexity advice. The clearest short piece on the topic.
https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0

EFF — Creating strong passwords
A practical method for building a passphrase, including the dice-based approach that guarantees genuine randomness.
https://ssd.eff.org/module/creating-strong-passwords

EFF — How to make a super-secure password using dice
A short animated overview of the same method, if you would rather watch than read.
https://ssd.eff.org/module/animated-overview-how-make-super-secure-password-using-dice

NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
The August 2025 standard behind the shift from complexity to length. Technical, but authoritative.
https://pages.nist.gov/800-63-4/sp800-63b.html

CISA — Use strong passwords
Plain-language guidance for the public from the US cyber security agency, including password managers.
https://www.cisa.gov/secure-our-world/use-strong-passwords

NCSC (UK) — Password managers: how they help you secure passwords
Where your passphrase fits: as the one credential protecting all the others.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers

Links checked in August 2026. If you would prefer resources in your own language, the national data protection authority or cyber security agency in your country usually publishes equivalent guidance — in Italy, the Garante per la protezione dei dati personali and ACN.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson works mainly on the Skills pillar at level FL1, and translates quickly into Secure Behavior.

Skills

  • Building passphrases that are strong and memorable at the same time.
  • Telling a secure passphrase from a predictable one — quotations, lyrics, proverbs.
  • Combining passphrase, password manager and MFA on your critical accounts.

For professionals and organizations

  • Recognising that a passphrase policy reduces support load: fewer written-down credentials, fewer resets.

Awareness

  • Understanding that length and randomness of words matter more than short, complicated tricks.
  • Seeing that a memorable quotation is not random, however personal it feels.

For future instructors and ambassadors

  • Being able to present passphrases as something an inexperienced user can adopt today, without a technical explanation.

Secure Behavior

  • Using passphrases for email, work accounts and sensitive services.
  • Replacing old, short passwords gradually — starting with the accounts that matter.
  • Keeping the passphrase for the password manager, and letting the manager handle everything else.

For organizations

  • Offering passphrases as the recommended default in internal guidance, rather than complexity rules alone.

G. Questions to sit with

  1. Which account would you give a passphrase to first, and why that one?
  2. How many of your current passwords are short enough to be guessed by a machine in minutes?
  3. If you were explaining passphrases to a colleague, a family member or a student, which example would convince them?
  4. What is holding you back from using passphrases everywhere — time, habit, the fear of forgetting one? What would make that easier?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply to this lesson.

Passwords and passphrases

  • R1 — Do not use the same password or passphrase across your accounts.
  • R2 — Use a password manager to store your passphrases, protected by a strong and unique master passphrase.
  • R3 — Make your passphrases longer than 16 characters, combining upper and lower case letters, numbers and symbols.
  • R4 — Turn on multi-factor authentication on critical accounts.
  • MS1 — Use the manager’s built-in generator to create credentials for individual services.
  • MS2 — Let the manager fill passwords in automatically: fewer errors, and less exposure to fake sign-in pages.
  • MS17 — For the email address linked to your bank: a unique, strong, randomly generated passphrase and mandatory MFA.

Devices, which protect the master passphrase

  • R5 — Set a six-digit PIN on the device where you use the password manager.
  • R7 — Keep screen lock time to a minimum.
  • MS4 — Use an alphanumeric passcode of at least 8 characters on your phone.

The minimum useful step

  1. Choose one critical account — your primary email or a work account.
  2. Create a long passphrase from random words, with a number and a symbol (R3).
  3. Save it in a password manager (R2, MS1, MS2).
  4. Turn on MFA for that same account (R4, MS17).

That is one evening’s work, and it changes the protection of the account everything else depends on.

In short

  • Four to six unrelated words beat a short, complicated password.
  • Randomness matters as much as length: no quotations, no lyrics, no sentences that make sense.
  • Use your passphrase where you have to type it from memory — above all, for your password manager.
  • Add MFA, and the passphrase no longer has to carry the whole weight on its own.

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program