A support person reads a guest Wi-Fi password aloud. An operator types a router login on a shared keyboard. A developer mints throwaway passwords for a test account. Those three jobs do not ask for the same string. The first two have to be typed. The third almost always lands in a password manager. A lot of people then meet xkcd 936: Tr0ub4dor&3 is ugly and still only about 28 bits, while correct horse battery staple — four ordinary English words — is about 44 bits. “Four words equals strong” leaked out of that comic and stuck.
The comic’s math has a premise people drop: each word is drawn uniformly at random from a list of about two thousand common words (the strip budgets 11 bits per word). Swap in a 100-word list and the same four words fall to about 27 bits — weaker than the cartoon, and far weaker than a 16-character random password. This article is not a tour of generator buttons. It answers when to use random characters, when to use a readable passphrase, and whether four words are enough. MyPassGen offers both modes with no account. Random mode defaults to 16 characters; readable mode draws 3–10 words from a built-in 100-word list. Every figure below is one you can recompute on a calculator.
Split the decision once
Will this secret be autofilled later? If yes, generate random characters at the default 16 or longer. If someone has to type it — guest Wi-Fi, a shared printer, a router you open twice a year — use a passphrase and push the word count to 8–10. Do not stop at four because the phrase is easy to say.
Ask whether a manager can fill it
NIST SP 800-63B-4, finalized on 31 July 2025, splits length from how a person enters the secret. When a password is the only factor, the verifier must require at least 15 characters. When it is one factor among several, the floor is still eight. Verifiers must also allow password managers and autofill, and they should allow paste when no autofill API is available. The document says managers raise the odds that people pick stronger secrets, especially when the manager ships its own generator.
The same revision drops two rules many sites still enforce. Verifiers shall not require mixed case, digits, and symbols as a composition policy. They shall not force periodic password changes unless there is evidence that this secret leaked. For the random-versus-passphrase choice, that is a clean split: if you can paste or autofill, there is no reason to give up entropy so the string is easier to pronounce. If you must type, use words to cut typos, then add words to put the entropy back.
MyPassGen’s random mode accepts 6–128 characters and defaults to 16, which sits in the same length band as the single-factor 15-character floor. Lengths below 8 show a weaker-password warning. That range is the generator’s own limit, not a claim that 6 characters “meets NIST.” If a site caps you at 8, take the full 8, turn on a second factor, and do not pretend an 8-character random string equals a 16-character one.
Two generation models
A random password and a readable passphrase are not two skins on one secret. They count guesses differently. Random characters draw one symbol at a time from a character pool: enable upper, lower, digits, and symbols, and the pool size is the sum of those sets. A passphrase draws from a fixed wordlist and joins the picks with a separator. If an attacker knows which list you used and how many words you took, the search space is “list size to the power of word count,” not “how long the sentence looks.”
Random characters add bits per position
With uniform draws, entropy is about length × log2(pool size). MyPassGen’s default four sets are 26 uppercase, 26 lowercase, 10 digits, and 18 symbols in !@#$%^&*()-_=+[]{} — 80 symbols in all. Sixteen positions at that pool is about 101 bits. Letters and digits only (62) at length 16 is about 95 bits. Drop the length to 8 and keep the 80-symbol pool, and you have about 51 bits. That is why a short “complex” password can look fierce and still sit in the same order of magnitude as a medium passphrase.
A passphrase adds bits per word
With uniform draws, entropy is about word count × log2(list size). Arnold Reinhold’s Diceware list and the Electronic Frontier Foundation’s 2016 long wordlist both have 7,776 entries — five six-sided dice, 65. Each word is about 12.9 bits. EFF’s usual advice is six words, about 77.5 bits. The comic’s four common words at 11 bits each are about 44 bits. That is a larger “everyday English” list, not a 100-word short list.
The draw has to come from a cryptographic source. MDN defines Crypto.getRandomValues as cryptographically strong random values. The same documentation marks Math.random() as not suitable for anything security-related and tells you to use Web Crypto instead. A “random password” or “random passphrase” built with Math.random() cannot honestly claim the full entropy of the formulas above.
Count entropy from the wordlist
The same sentence — “four words” — can differ by a factor of two once you change the denominator. log2(100) is about 6.64, so four words on a 100-word list are about 27 bits. log2(7776) is about 12.92, so four Diceware words are about 52 bits. The comic’s 11 bits per word gives about 44. Quoting the word count and hiding the list size is the usual way a readable password gets written up as stronger than it is.
Tacking on one digit or one symbol adds only a small extra choice: ten digits are about 3.3 bits, a short symbol set is about 3. MyPassGen’s readable mode, if you enable an inserted digit or symbol, adds about 6 bits each on the on-page estimate. That is a generous internal ruler, not “one ! almost equals six Diceware words.” Capitalizing the first letter of each word is scored at about 0.5 bits per word — a nudge, not a tier change. To push a 100-word passphrase into the generator’s Strong band (55 bits on that meter; this article’s shared ruler treats “strong” near 60), you need 8–10 words, not 1! after four.
Picking the words yourself is worse. A lyric, a film title, or the name of the current sprint already lives on attackers’ phrase lists. You do not get “list size to the fourth power” for a sentence you can remember. A passphrase only earns the formula when the words are uniform draws from a known list, not a line you already liked.
100 words, 7,776 words, random strings
The table uses one formula throughout. “100 words” is MyPassGen’s built-in readable list. “7,776 words” is Diceware / EFF long. Random strings use an 80-symbol pool. The labels on the right are a single ruler so the two formats can sit on one page: below about 40 bits weak, below 60 medium, below 80 strong, above that very strong. That is a scale for you to read, not a promise about any particular GPU. The generator’s own passphrase meter uses 40 / 55 / 70, so ten 100-list words (about 66 bits) read Strong there, and six Diceware words (about 77.5 bits) read Very strong.
| Method | About | On this ruler |
|---|---|---|
| 100-word list × 4 words | ~27 bits | Weak |
| 100-word list × 6 words | ~40 bits | Medium (just over the line) |
| 100-word list × 8 words | ~53 bits | Medium |
| 100-word list × 10 words | ~66 bits | Strong |
| Diceware 7,776 × 4 words | ~52 bits | Medium |
| Diceware 7,776 × 6 words | ~77.5 bits | Strong (EFF’s usual size) |
| Random 8 characters (80-symbol pool) | ~51 bits | Medium |
| Random 16 characters (80-symbol pool) | ~101 bits | Very strong |
Take two facts from the table. First, a default 16-character random password is the cheapest “very strong” row: you do not memorize it; the manager fills it. Second, a readable mode that stops at four words sits near a short random string or the rewritten dictionary word in the comic. Being easy to say does not promote it. When you must type, run the 100-word list to 8–10 words, or accept the length of six Diceware words. Do not line four short-list words up against 16 random characters.
NIST’s single-factor 15-character floor is a length minimum, not an entropy minimum. Fifteen characters from an 80-symbol pool is about 95 bits — the same band as the default 16. Four common English words, even at the comic’s 44 bits, still sit below the random string that length implies. A typed secret has to stay typeable and stay in the right order of magnitude. You get there by adding words, not by adding @.
Common mistakes
“Four words is the xkcd password” only holds if the list and the random source match the comic or Diceware. Hyphenated English words on a screen do not prove 11 or 12.9 bits per word.
“A passphrase is always weaker than random characters” is also false. Six Diceware words are about 77.5 bits, already Strong on this ruler. Ten words from a 100-word list are about 66 bits, also Strong. What is weak is a short list plus too few words, not the fact that the secret is made of words.
“Add 123 and an exclamation mark and it is fixed” does almost nothing to a short human-chosen password: those suffixes are already in dictionaries. On a uniformly random word string, one extra digit is a few bits. It does not replace two extra words.
“The site can emit a passphrase, so the result must be strong” depends on the list. Some pages use 7,776 words. Some use a few hundred themed nouns, or fewer. Before you trust the output, ask three things: how long is the published list? Is the source getRandomValues? Did the result leave the tab as business data? A slogan is not an answer to any of those.
“HTTPS means the password cannot leak” only covers eavesdropping on the wire. If the generator POSTs the result, or writes the secret into an analytics event, HTTPS still delivers plaintext to that host. The check is in How to verify that browser encryption did not upload plaintext: read the Network request line and body, not the padlock.
Do not paste a fresh password into a strength site that uploads the string
Some checkers POST the password. Others send only a hash prefix. A local check downloads a public weak-password list and leaves the candidate in the box. The difference is in Local leaked-password lists vs Have I Been Pwned: what each check proves. Generation and the local check both open without an account.
Check it on the spot
These steps do not depend on a brand promise. Use a string you will not put on a real account.
- Open the generator, pick the readable passphrase, set the word count to 4, and generate once. Note the on-page strength label and entropy. On the table above, 100 words × 4 should land near Weak (about 27 bits).
- Raise the count to 8 or 10 and generate again. The label should move up; 10 words should approach Strong. Do not “improve” the result by swapping in four words you thought of.
- Switch to random characters, leave length at the default 16, keep all four character types on, and generate. The label should be Very strong (about 101 bits). Put the three results side by side: four readable words should not outrank the 16-character random string.
- Open DevTools Network, enable Preserve log, and generate once more. Document requests and analytics events should not contain the password still on the page. The random source should be Web Crypto, not
Math.random()in the page script — search that name under Sources if you want to confirm. - If you also want a public weak-password list, paste an old password you plan to retire into the local checker. Do not send a new primary password to a site that uploads the string. A miss only means it is not on this list. It does not mean “never dumped.”
MyPassGen’s password generator is built on that boundary. Both modes draw with getRandomValues in the current tab. Random mode is 6–128 characters, default 16, with a weaker warning below 8. Readable mode is 3–10 words from a 100-word list; you can add a separator, a digit, a symbol, or initial capitals. You can mint up to 100 strings at once, copy them, or export a TXT file. There is no account and no password vault. Close the tab and those strings are not sitting on the server. What you verify is Network, not the headline.
How to choose the next password
For the secret you will rotate today, answer the manager question first. If autofill will handle it, generate 16 random characters or longer, one string per site, no reuse. If it has to be typed, generate an 8–10 word passphrase. Read it aloud once to the person next to you. Do not paste the same string into a group chat “as a backup.” When the recipient is remote and the secret should exist once, use a one-time link and keep the key after # in the URL instead of making a second plaintext copy.
Routers, guest Wi-Fi, and printers are the usual typed cases: visitors use a phone keyboard, and mixed case plus symbols produce 0/O and 1/l mistakes. A longer word string is harder to mis-hear and mis-copy than an 8-character “complex” random password. If the admin panel is rare and you carry a manager on your own device, still prefer 16 random characters for that login. Do not reuse the Wi-Fi phrase as the router password.
Once you have made that split, the article’s question is answered. Random versus readable is an input question. Whether four words are enough is a wordlist question. Four words on a 100-word list should not carry an important account. A default 16-character random password can. The on-page label should match this table. If it does not, do not trust “it looks like a sentence, so it is safer.”
FAQ
Can a four-word passphrase be a master password?
Not on a 100-word list. About 27 bits is a short random string. A master password, a disk-encryption passphrase, or any secret you rarely rotate and would regret leaking should be 16 or more random characters stored in a manager, or 8–10 randomly drawn words — not a sentence you invented.
Should I add case and symbols so the site’s complexity rules pass?
If the site still demands mixed character types, turn on an inserted digit, symbol, or initial capitals so the form accepts the string. That satisfies a stale spelling rule. It is not the main source of entropy. NIST already tells verifiers not to impose those rules. After the form accepts the password, judge it by word count and list size.
Do I need an account to generate a random password or a passphrase? Is the result uploaded?
No account. Generation should stay in the current tab. The log risk starts when you hand the result to a site that uploads the string. Open Network after you click generate: the request body and analytics events should not contain that password. If you need a copy, copy or export it to a place you already trust. There is no in-site vault.
For a typed Wi-Fi password, 16 random characters or a passphrase?
It depends who types. If only you connect through a manager, use 16 random characters. If guests regularly type on a phone, use 8–10 words and avoid 0/O, 1/l, and a pile of symbols. Do not reuse that Wi-Fi phrase on the router admin page.