The modern rule, straight from NIST's digital identity guidelines: length matters more than complexity. A four-word passphrase like "copper-lantern-mango-drum" — 24 characters, memorable, typeable — is stronger than "P@ssw0rd!23" and survives shoulder-surfing better too. The method: pick four-plus random words, join them, add nothing clever. The catch: any passphrase you reuse across sites loses to the first site that leaks it — uniqueness, not cleverness, is what a password manager is for.
Why did the old password rules change?
The original rules — short minimum lengths, mandatory symbols, forced rotation — produced what users actually do: "Summer2024!" then "Fall2024$". NIST's revision (SP 800-63B) documented the failures and now recommends: longer minimums (its guidance suggests allowing 64+ characters), no mandatory periodic rotation (rotation drives weak patterns), checking new passwords against known-breach lists, and dropping composition rules that push predictable substitutions. The hacker-proofing moved from games with symbols to sheer length.
How do you make a passphrase you'll remember?
- Pick words at random, not associatively — not your dog, your street, your birthday. Roll dice against a word list (the EFF's large wordlist is the documented tool for exactly this) or grab four words from different pages of unrelated books.
- Join with hyphens or spaces where sites allow: "copper-lantern-mango-drum".
- Length-check: 16 characters minimum; four to six words gets you there naturally.
- Test nothing — never paste a real password into an online "strength checker"; the checking is what a checker does with your password.
Where should passphrases be used?
- Master passwords — the one password a manager can't store for you: a five-six-word passphrase is the documented sweet spot of memorable and uncrackable.
- Device logins you type weekly — phones (as PIN backup), computers, disk-encryption passphrases.
- Wi-Fi passphrases — three-plus random words per CISA's home-network guidance, shareable by reading aloud.
Everything else — the hundred site logins — belongs in a password manager generating random 20-character strings you never memorize.
What makes a passphrase weak?
- Famous phrases: "to-be-or-not-to-be" appears in every cracking dictionary — the words must be random, not quoted.
- Personal patterns: dog-name-city-year collapses to a guessable pattern the moment any of it leaks.
- Reuse: the documented killer — one breach, everywhere reused, per credential-stuffing reporting.
The verdict
One five-word passphrase for your master password, unique manager-generated strings for everything else, breach-checks where offered (Chrome, Safari and Firefox document them built-in). That's the entire modern discipline — and it fits on an index card, which is exactly where your emergency master-passphrase hint doesn't belong.
FAQ
For more context, read How to Check if Your Data Was Exposed in a Breach — and What to Do Next.
For more context, read buy refurbished electronics guide.
For more context, read How to Declutter Your Digital Life in One Weekend.

