Passphrase Generator

Create a strong, memorable passphrase from random words — inspired by the famous XKCD comic. Long and random beats short and complicated.

Crack times shown assume the attacker knows this is an XKCD-style passphrase (word list + chosen separators + the rules this generator uses) — i.e. a worst-case targeted attack. If the attacker does not know the structure, the real time is far higher.

Why Use a Passphrase?

The famous XKCD comic "Password Strength" showed that four random common words — like "correct horse battery staple" — are far harder to guess than a short password like "Tr0ub4dor&3". Length beats complexity: each extra word multiplies the combinations exponentially.

This generator picks words from a curated list of common, easy-to-spell English words. With four words you get over 40 bits of entropy, and adding a number or symbol pushes it even higher. All generation happens locally in your browser.

Combine your passphrase with a password manager, and you get both security and memorability — the best of both worlds.

Frequently Asked Questions

What is an XKCD passphrase?

Inspired by the XKCD comic "Password Strength", a passphrase is a sequence of random common words joined by a separator. It is long, easy to remember, and surprisingly hard to brute-force because every extra word multiplies the possible combinations.

Is a passphrase stronger than a password?

At equal length, yes. Four random words give roughly 40+ bits of entropy while remaining easy to type and memorize. Adding a number or symbol increases the entropy further.

How many words should I use?

We recommend 4 to 6 words. Four words give a solid baseline; five or six provide significantly more security for high-value accounts like email or banking.