Easy to remember. Hard to guess.
Random words can make useful credentials. The word selection matters more than the story you invent afterward.
A passphrase is more than a sentence
A familiar quotation or song lyric is easy for an attacker to try. A random passphrase chooses each word independently from a large list. You can build a mental story around the words afterward, but choosing the words to fit an existing story sacrifices the randomness that makes the method useful.
How PasswordCraft selects words
The generator uses the Electronic Frontier Foundation’s long list of 7,776 distinct words. Each position is chosen independently using Web Crypto and rejection sampling. Repeated words are allowed: a repeat is a legitimate outcome of independent random draws. The wordlist is public; security depends on the number of possible sequences, not secrecy of the list.
What the entropy number means
One selection from 7,776 equally likely words has log₂(7,776), about 12.925 bits, of entropy. Six words have about 77.5 bits. This counts possible generated sequences; it is not a cracking-time guarantee. The protection provided by a service also depends on how it stores and limits guesses against credentials.
Separators improve readability
Choose a hyphen, space, underscore, or period to separate words. A fixed separator adds no random entropy. Check that the service accepts the resulting length and punctuation. If you modify words or choose a shorter phrase for convenience, the generator’s entropy calculation may no longer describe your final credential.
Make it memorable without changing it
Picture an unusual scene that links the generated words in order. Rehearse it privately, and save the exact text in your password manager while you learn it. Never reuse a published example. If a phrase feels inconvenient, generate a fresh one rather than replacing words with familiar choices.
Choose the right use case
Passphrases can help for credentials you must type or remember, such as a password-manager master password. For credentials filled automatically, a long random character password is usually convenient. Add multifactor protection and plan recovery for either option.