# Explicitly mention to use no less than 4 words when making a random passphrase, in the Intro to Passwords article

**URL:** https://discuss.privacyguides.net/t/explicitly-mention-to-use-no-less-than-4-words-when-making-a-random-passphrase-in-the-intro-to-passwords-article/27259
**Category:** Site Development
**Tags:** completed
**Created:** 2025-05-03T23:16:22Z
**Posts:** 24

## Post 1 by @anonymous261 — 2025-05-03T23:16:22Z

> **[Law Enforcement Can Break 77% Of ‘Three Random Word’ Passwords](https://www.forbes.com/sites/daveywinder/2025/04/27/now-law-enforcement-can-hack-77-of-three-random-word-passwords/)**
>
> It’s time to change how you create your passwords — here’s what you need to know.

Maybe you could also mention [StrongPhrase.net](http://StrongPhrase.net) when suggesting ways to generate random passphrases?

---

## Post 2 by @jonah — 2025-05-04T03:07:48Z

Seems pretty uncontroversial to mark this as #approved and accepting PRs :+1:

I don’t know about recommending a specific password generator necessarily, but I think that warrants its own separate discussion.

> [@StrongPhrase.net - Random passphrases, passcodes, usernames, and identities](https://discuss.privacyguides.net/t/strongphrase-net-random-passphrases-passcodes-usernames-and-identities/25813):
>
> Hi folks! I created [StrongPhrase.net](http://StrongPhrase.net) about a year ago and have been adding little utilities to it over time. I wanted to share it with y’all and invite your feedback! [https://strongphrase.net](https://strongphrase.net) History: The core passphrase algorithm was created by [Ryan Foster](https://getapassphrase.com/) and I wanted to add a more modern UI around it. I then went on to write a deep FAQ about password entropy as a way to study the topic myself. It has a few features: Passphrase generator + FAQ Phone passcode generator Username generator I…

---

## Post 3 by @ph00lt0 — 2025-05-04T17:40:56Z

Not really sure what is the benefit. Just use your password manager for this.

---

## Post 4 by @anonymous261 — 2025-05-04T18:06:53Z

I should make a new topic asking about StrongPhrase, but here are some of the strengths it has compared to most other password generators

> [@StrongPhrase.net - Random passphrases, passcodes, usernames, and identities](https://discuss.privacyguides.net/t/strongphrase-net-random-passphrases-passcodes-usernames-and-identities/25813/22):
>
> Hi @AtomicBug! I can’t believe I’m only discovering your site now. It’s extremely promising! I love it! WHY THIS IS AWESOME! A true passphrase generator should create an actual sentence with nouns, verbs, and adjectives, and numbers, that describe an action. For years, I have been annoyed with the fact that the passphrase generators in password managers, and passphrase generator websites in general, don’t actually generate phrases but just random words. Yes, random words on their own are e…

---

## Post 5 by @Machkiel — 2025-05-04T21:27:45Z

Today was my first time seeing [StrongPhrase.net](http://StrongPhrase.net), and the concept is great.

With that being said, I disagree with allowing a third-party to provide or even recommend passphrases. For example, clearnet users could have their IP address logged with a list of passphrases they were shown or copied from the page.

Even as a Tor user, I do not believe that is a good practice.

---

## Post 6 by @crossroads — 2025-05-05T04:35:53Z

Password managers have option to capitalize words, add numbers and special characters, so even a 3-word pass can be a bit stronger. But yes, 4 words should be recommended as a minimum. Problem is, there are services that limit passwords to 20 characters, and it’s almost impossible to have good passphrase in that case.

And I see passkeys are mentioned 8 times in that text, and 2FA only once, which tells me someone has a horse in this race :slight_smile:

---

## Post 7 by @redoomed1 — 2025-05-15T13:34:32Z

> <https://github.com/privacyguides/privacyguides.org/pull/3043>
>
> List of changes proposed in this PR:
> 
> - Recommend <del>4</del> 6 words as the …minimum word length for randomly generated passphrases
> - Relevant discussion: https://discuss.privacyguides.net/t/explicitly-mention-to-use-no-less-than-4-words-when-making-a-random-passphrase-in-the-intro-to-passwords-article/27259
> - Make minor grammar and style changes

---

## Post 8 by @fria — 2025-05-17T18:19:01Z

The benefit would be for certain things like your phone password that you can’t really use your password manager for. For those cases having a minimum number of words is important. I think 4 words is too low though, the [EFF recommends](https://www.eff.org/dice) at least 6 words.

---

## Post 9 by @ph00lt0 — 2025-05-17T18:55:02Z

why can’t you use your password manager for that?

---

## Post 11 by @phnx — 2025-05-17T19:00:32Z

I completely agree, the recommendation should be 6-10 words from the EFF Large Wordlist. This is better in line with what other experts recommend.

---

## Post 12 by @fria — 2025-05-17T19:03:31Z

Obviously you can’t get your password manager open if your phone is locked, and whatever device your password manager is on would need to be running that would be attacked and they would get your encryption password that way. Better to memorize it, that’s the whole point of diceware anyway, to have a memorable passphrase.

---

## Post 13 by @TinFoilHat — 2025-05-17T19:17:31Z

Depend on what keyboard you use, you might be able to use emojis or UTf-8 characters, which could produce strong password without making it too long

---

## Post 14 by @ph00lt0 — 2025-05-17T19:39:01Z

Yeah and you can create those easily with your passeord manager… honestly not understanding your point.

---

## Post 15 by @fria — 2025-05-17T20:07:24Z

For creating them? Sure, but maybe the password manager doesn’t give a good minimum or maybe it doesn’t have a minimum length at all. Also not every password manager even has a diceware generator.

---

## Post 16 by @dumdum — 2025-05-17T20:29:31Z

Isn’t using more than 7 words from the EFF large wordlist providing more entropy than an average person could reasonably need for a passphrase? Unless the attacker is a state agency, 90 bits (7 words) of entropy is fine for pretty much anything, while 128 bits (10 words) is for if you want to future-proof. It depends on the person, but personally for me, a 10-word “EFF passphrase” is quite hard to remember and cumbersome to type. Especially when some of the words included are pretty rare and unconventional.

This is partially why I also think that StrongPhrase does serve a purpose. It is true that password managers are capable of creating passphrases for you, and StrongPhrase’s system is less efficient compared to the EFF wordlist. However, even a 12-13 word StrongPhrase passphrase is much easier to remember because the words are more common and easier to type because it flows like a regular sentence would.

---

## Post 17 by @phnx — 2025-05-17T21:04:27Z

> [@dumdum](#):
>
> Isn’t using more than 7 words from the EFF large wordlist providing more entropy than an average person could reasonably need for a passphrase?

Arguably yes, which is why it makes sense to give a recommended range. Even with the most extreme threat models you reach a point of diminishing returns where the entropy of the passphrase exceeds that of the algorithms being used.

For example, Android uses AES-256 for encryption so there is absolutely no reason to have a passphrase with \>256 bits of entropy since you AES-256 will only accept a 256 bit key which is derived from the password using a KDF (key derivation function).

Personally I use a 10 word passphrase (~129 bits entropy) which will remain theoretically secure for the foreseeable future. I would argue more than that is basically completely pointless.

---

## Post 18 by @CarefulMouse — 2025-05-17T21:15:53Z

For iOS and Pixel I was under the impression a numeric PIN was sufficient due to the nature of Aseries/Tensor. Based on this thread that is not true so I’ll be reading closely. Glad this is being discussed, and I may need to revisit this.

---

## Post 19 by @phnx — 2025-05-17T21:21:06Z

Your understanding is correct, the vast majority of people are perfectly safe using a 6-8 digit PIN on devices with the Titan M2 or iPhones since the 12 (I think). It’s just that then you are depending on those secure elements not being compromised in the future. They are holding up extremely well so far though so it’s really not something I would worry about unless you have an extreme threat model.

Further reading:  
[https://xcancel.com/GrapheneOS/status/1791837791887729143#m](https://xcancel.com/GrapheneOS/status/1791837791887729143#m)

> **[GrapheneOS Frequently Asked Questions](https://grapheneos.org/faq#encryption)**
>
> Answers to frequently asked questions about GrapheneOS.

---

## Post 20 by @Prismatic — 2025-05-19T05:59:29Z

Recommending a strong password is good, but the choice of any specific number of words is arbitrary. Here alone in this post suggestions range from 4 to 10 words (52 bits to 129 bits). It’s meaningless without an appropriate threat model. Secure against what? Against basic mass password cracking 4 words may be enough, but 6 words may be on the low end against law enforcement (the threat model in the article), while 10 words is arguably overkill for even the highest threat models.

* * *

The study referenced by the article is about improving digital forensics and is not cyber security advice. It “explores rule-based optimization strategies to enhance the effectiveness of password cracking while minimizing resource consumption.” It states the following:

> Results indicate that while three-word passwords provide improved memorability and usability, they remain vulnerable when common word combinations are used, with up to 77.5% of passwords cracked using a 30% common-word dictionary subset.

Note that:

- It is already known that 3-word passphrases _can_ be cracked. The study is about doing so more efficiently.
- The study is not done by law enforcement and the methods are not limited to law enforcement.
- The choice of 3-word passphrases is based on the UK National Cyber Security Centre’s (NCSC) three-word password guideline. It **DOES NOT** state that 4 or more words are secure.
- The passwords are **NOT RANDOM**. The passwords cracked were either part of previously breached passwords (eg Rockyou) or part of a user survey where participants were asked to create a password composed out of three dictionary words of at least eight characters each.

---

## Post 21 by @PurpleDime — 2025-05-19T06:15:42Z

> [@Machkiel](#):
>
> I disagree with allowing a third-party to provide or even recommend passphrases.

You disagree with the existence of websites like **[Strong Phrase](https://strongphrase.net)** and [**Get a Passphrase**](https://getapassphrase.com/)?!  
That doesn’t make sense to me. You’re implying that those generators are not safe. That is a bold claim.

I would also argue that using your password manager’s generator is also using a third party. Anything short of you coming up with your own passphrase is using a third party. And we all know how terrible of an idea it is to come up with passphrases on your own.

Moreover, **Strong Phrase** doesn’t have word separators (a recommendation I made) or special characters. Most websites require that you include special characters in your password. We now know that’s not the best of recommendation, as the length of a password is more important than the variety of its characters. And yet many websites still won’t allow passwords longer than 16 to 20 characters, but that is beside the point.

My point is, it is fair to assume that anyone in this community who uses passphrase uses special characters, because it is a requirement from most websites. Doing so, makes their passphrases different from the one they generated.

But even if they were identical, I don’t think it is unsafe to use websites like **Strong Phrase**.

---

## Post 22 by @Machkiel — 2025-05-20T18:34:28Z

@PurpleDime

Allowing a Web site to generate a passphrase introduces unnecessary risk that would not exist if a local application (for example, KeePassXC) generated the passphrase. Perhaps my systems differ from yours, but on my systems KeePassXC does not have Internet access.

I can neither vouch for nor malign the Web sites that generate passphrases, but I will not be using them.

---

## Post 23 by @anon39279085 — 2025-05-20T18:42:46Z

that’s a completely different story, it doesn’t mean they’re outright not recommended tools to use, in fact it’s less attack surface to use webapps than to rely on an app AND in fact you can download the [Get a Passphrase](https://getapassphrase.com/) page and use it completely offline (the css, js and everything gets bundled in and works as it should so that’s cool), invalidating your claim.

---

## Post 24 by @jonah — 2025-05-20T18:46:28Z

This change has been #completed with a **6 word recommended minimum** :

> <https://github.com/privacyguides/privacyguides.org/pull/3043#discussion_r2094182066>
>
> ```suggestion
> If you don't have access to or would prefer to not use real dice,… you can use your password manager's built-in password generator, as most of them have the option to generate diceware passphrases in addition to regular passwords. We recommend setting the generated passphrase length to at least 6 words.
> ```
> 6 words is the minimum recommended by the [EFF](https://www.eff.org/dice). With the advent of quantum computers I think it’s important to make sure people’s passphrases have enough entropy, especially since they’re mostly going to be used for encrypted drives which can be brute forced.

As such I will lock this thread. As a reminder since there are recent comments here, we _always_ lock all site development threads when they are completed, but if you have a question about passphrase strength you’re more than welcome to start a new topic in #Questions, or if you think we should make an additional/different change you can always start a new topic in #Site Development :slight_smile:

---

## Post 25 by @jonah — 2025-05-20T18:46:30Z

#completed:

> **[update: Recommend minimum length for passphrases (#3043) ·...](https://github.com/privacyguides/privacyguides.org/commit/75ba4fe003959d04b54d48662ff1ab3206d67de3)**
>
> Signed-off-by: Freddy 
> Signed-off-by: fria

---

## Post 26 by @redoomed1 — 2025-07-21T03:12:45Z

In Progress → Done
