← All terms

Passphrase

A passphrase is a password built from a sequence of words — long enough to resist cracking, memorable enough for the few secrets no tool can store for you.

A passphrase is a password constructed from a sequence of words — correct-horse-battery-staple rather than Tr0ub4dor!. The idea is to get security from length instead of from symbol-substitution tricks, because length is what actually determines how long a secret survives a guessing attack, and words are what human memory is actually good at storing.

How it works

Every added character multiplies the number of combinations an attacker must try, which makes a 25-character sequence of common words astronomically harder to crack than an 8-character jumble of symbols — and far easier to type and remember. The caveat is predictability: a famous quote or song lyric sits in every cracking wordlist, so the words need to be effectively random. Current NIST guidance (SP 800-63B) is built around this trade: it asks verifiers to drop composition rules entirely, support long passwords, and require a 15-character minimum where a password is the only factor — length over theater.

Passphrases matter most for the handful of secrets that cannot live in a vault. A password manager should generate and store virtually every credential an employee uses, but the master secret that unlocks the vault, the login to the laptop itself, and the recovery credentials for core identity systems still have to pass through a human brain. Those are exactly the secrets that brute-force and spraying attacks target, and exactly where a weak memorable choice does the most damage.

How to defend

Write the policy so it matches the tooling: vault-generated random credentials everywhere a manager can reach, and a long random-word passphrase — four or more words, no famous phrases — for the few secrets it cannot. Drop forced rotation and composition requirements, which push people back toward predictable patterns, and screen new choices against breached-password blocklists instead. Our guide to rolling out a password manager covers how to sequence the policy change, and the long-term direction is to need fewer memorized secrets at all as passkeys take over.

Related terms

Password ManagerA password manager generates, stores, and autofills unique credentials — a core defense against credential stuffing, password reuse, and lookalike phishing sites.Brute-Force AttackA brute-force attack tries passwords or keys systematically until one works. Weak, reused passwords make it cheap — MFA and passkeys make it pointless.Password SprayingPassword spraying is a brute-force technique that tries a few common passwords against many accounts, staying under lockout thresholds while hunting weak credentials.PasskeyA passkey is a phishing-resistant FIDO2/WebAuthn credential — a cryptographic key pair bound to one website — that replaces passwords and one-time codes.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo