English

Text & everyday tools · Password Generator

Passphrase or random password? Choosing by where you have to type it

· Why it matters

passwords passphrases usability

A hand entering a word-based secret beside a password-manager autofill symbol
Original ToolAcre vector illustration

Argues that the right format depends on the input surface — a phone keyboard, a TV remote, a disk-encryption prompt or a password manager's autofill — and gives a decision rule for each.

Typing Xq7$v!2p on a television remote — where random passwords fail in practice

A string such as Xq7$v!2p may be awkward to enter with a TV remote. Difficulty for the legitimate owner is not the same as difficulty for an attacker, especially when a short, human-chosen “clever” password uses predictable substitutions. For credentials you must type often, random words can reduce transcription mistakes while allowing a longer secret. For credentials a manager fills automatically, memorability buys little: choose a long unique random value and never read it aloud.

The two formats compared — memorability, typing speed, error rate and strength per character

A passphrase is a sequence of words selected uniformly from a sufficiently large list; a random password selects characters from a stated alphabet. Both can be strong when their source is cryptographic and the result is long enough. Strength “per character” is not a useful universal ranking because input alphabets, list size and selection habits differ. A phrase a human invents from favourite words is not equivalent to several machine-selected EFF words even when its typography looks similar.

Passwords a human types — device logins, disk encryption, Wi-Fi and the manager's master password favour passphrases

A laptop login, disk-encryption prompt or password-manager master password may have to be typed before autofill is available. Those are good candidates for a memorable randomly generated passphrase if the system accepts its length and spaces. A Wi-Fi router label or remote-control keyboard may have narrower character rules; test what the device accepts before generating a phrase you cannot enter. If the account requires a second factor, use it—no arrangement of words protects a secret typed into a phishing page.

Passwords a machine fills — website logins stored in a manager can be long random strings nobody ever reads

A website login held in a manager is different. The manager can create and fill a long random string that no person memorises and assign a different one to every account. Reuse is a risk even for a statistically strong phrase; one compromise should not unlock the rest of your services. The master credential and each stored site password have different jobs, so giving both the same format for “consistency” is not a security plan.

Length limits and field rules — where a passphrase does not fit and what to do instead

Some old systems reject spaces, truncate long input or impose tiny maximum lengths. Ask whether the limit applies to characters, bytes or a particular encoding, especially with non-ASCII words. Where a passphrase will not fit, choose a random password from the allowed alphabet and as much length as the service accepts. Do not silently chop several generated words off a phrase and continue quoting the old entropy estimate. If a provider forces unusual composition rules, your generator needs to obey them without turning the result into a personal pattern.

Worked example — assigning a format to each account created during a new-laptop weekend

On a new-laptop weekend, choose a fresh multiword phrase for the disk unlock and another for the manager’s master password; never share one between them. Let the manager produce distinct random strings for new web accounts. For a router, check its accepted Wi-Fi credential rules first, then generate a long value that can be entered or provisioned reliably on your devices. None of these examples is a reusable password suggestion: generate your own secrets with Web Crypto and store them safely.

What this does not cover — hardware security keys and passkeys, which replace passwords altogether

This comparison does not replace hardware security keys, passkeys, account recovery controls or phishing-resistant multi-factor authentication. A password manager can also be compromised if its device is compromised, so choosing the input format is only one layer. NIST guidance emphasises length and avoiding arbitrary composition tricks, but the service implementing a credential still defines its actual accepted limits.

The takeaway — for anything you type by hand, generate a passphrase with the Password Generator and let your manager handle the rest

For something a human must type repeatedly, generate a random passphrase where the input surface permits it; for something a machine fills, delegate uniqueness and length to a trusted password manager. ToolAcre Password Generator uses browser cryptographic randomness and keeps generated values on the device, with no third-party ad or analytics script on its password pages. Verify your device and clipboard are trusted before using any web-based generator for a high-value secret.