Symlex VPN | Password vs passphrase: How do I make a strong password?

IP Status: Checking...

Password vs passphrase: How do I make a strong password?
Aynun Nipa • February 7, 2024 • 5 min read

Password vs passphrase: How do I make a strong password?

Share On
In this article Table of Contents
    Stay private. Stay protected.

    Browse, work, and stay connected with greater privacy and a more secure internet connection.

    Table Of Contents

      Stay private. Stay protected.

      Browse, work, and stay connected with greater privacy and a more secure internet connection.

      In the password vs passphrase discussion, neither option is automatically secure. A traditional password may use random characters. A passphrase typically uses several words. Length, randomness, uniqueness, storage, and account security controls all matter. In this guide, we will help you understand current password and passphrase standards.

      What is a password?

      A password is a secret value used to verify that you are allowed to access an account, device, application, or other protected system. A strong password should be long, difficult to guess, and unique to the account where you use it.

      Older advice often focused heavily on adding uppercase letters, lowercase letters, numbers, and symbols.   Current NIST guidance emphasizes length and avoiding commonly used or compromised passwords instead of forcing specific character combinations. 

      As a result, you require at least 15 characters when a password is the only authentication factor. Passwords used only as part of multi-factor authentication may be at least eight characters.

      What is a passphrase?

      A passphrase is essentially a longer password created from multiple words. Instead of trying to remember a short string filled with symbols, you could use several unrelated words. 

      The important part is that the words should not form an obvious quotation, personal fact, common phrase, or predictable sentence. NIST notes that passphrases can effectively create longer passwords. 

      The UK’s National Cyber Security Center also recommends combining random words because a longer credential can be easier to remember without relying on predictable character substitutions. 

      Data source: National Cyber Security Center

      Password vs passphrase comparison

      FeaturePasswordPassphrase
      FormatCharacters or generated stringsMultiple words
      LengthCan be short or longUsually longer
      MemorabilityRandom passwords can be difficult to rememberCan be easier to remember
      StrengthStrong when long, random, and uniqueStrong when long and based on unrelated words
      Best storagePassword managerPassword manager or securely memorized
      Main riskReuse, predictability, phishingPredictable phrases, reuse, phishing
      MFA recommendedYesYes

      The important point is that length alone does not make every passphrase safe. A long quotation or familiar saying can still be predictable.

      How do I make a strong password?

      If you search for how do I make a strong password, start with three basic rules: make it long, make it unique, and avoid predictable information.

      A practical strong password should:

      • Be at least 16 characters when the service supports it
      • Be unique for each account
      • Avoid names, birthdays, addresses, and phone numbers
      • Avoid common passwords and predictable patterns
      • Avoid simple changes such as replacing o with 0
      • Be generated and stored with a trusted password manager when practical

      Password reuse is particularly risky. If one service experiences a credential breach, a reused password may put other accounts at risk too.

      How to create a passphrase

      Learning how to create a passphrase is fairly simple. Start by selecting several unrelated words. CISA currently suggests a memorable passphrase made from five to seven unrelated words as one way to create a long credential. 

      A fictional passphrase example could follow a pattern such as:

      River Lantern Mango Bicycle Velvet

      Do not use that exact example as a real password. Anything published online should be considered known.

      Avoid phrases such as:

      • Famous quotations
      • Song lyrics
      • Movie lines
      • Your home address
      • Family names
      • Pet names
      • Birthdays
      • Common expressions

      Randomness and uniqueness matter more than sounding natural.

      Are passphrases more secure than passwords?

      Not automatically.

      • A randomly generated 25-character password can be extremely strong. A long passphrase can also be strong if you choose its words unpredictably.
      • A weak passphrase made from common words in an obvious pattern may be easier to guess than a properly generated random password.

      This is why the password vs passphrase choice should not be reduced to “passphrases are always safer.”

      Should you use a password manager?

      For most people managing many accounts, a password manager is useful. It can generate unique credentials for every account and store them, so you don’t need to memorize dozens of passwords. 

      • Protect the password manager itself carefully. 
      • Use a long, unique master password or passphrase and enable MFA when supported.

      Why passwords and passphrases are not enough

      NIST states that passwords are not phishing-resistant. Length and complexity also don’t prevent someone from entering a password on a convincing phishing site or exposing it through malware.

      This is why you should also:

      • Enable multi-factor authentication
      • Watch for phishing messages
      • Keep devices and browsers updated
      • Use unique credentials for every account
      • Change passwords when you know or suspect they have been compromised

      CISA recommends MFA as an additional layer of account protection beyond a password.

      Data source: NIST, CISA

      A VPN can protect traffic between your device and a VPN server, but it does not make weak passwords stronger and cannot stop you from entering credentials into a phishing site.

      Do you need to change passwords regularly?

      Current NIST guidance does not recommend forcing password changes on a fixed schedule without a reason. Instead, change a password when there is evidence or a reasonable concern that it has been compromised. This avoids encouraging predictable changes.

      Final words

      The password vs. passphrase decision matters less than how you create and protect the credential. A strong password can work well when it is long, random, unique, and stored securely. A passphrase can also protect an account well when it uses several unrelated words and avoids predictable personal information.