Free security tool
Citadel Passphrase Generator
Create a strong passphrase you can actually remember.
Choose how many words you want, click generate, and your new passphrase is ready to use. Longer passphrases are harder to guess, while random words make them easier to remember than a complicated string of characters.
Private browser tool
Build your passphrase
Your new passphrase
Your passphrase was not saved
Citadel Networks does not know what was generated.
The generator runs locally inside your browser using its cryptographically secure random-number generator. The result is not transmitted to Citadel Networks, included in analytics, or written to server logs.
Once you leave or refresh this page, the displayed passphrase disappears and a fresh one is generated.
A brief cybersecurity lesson, with pictures
Why Passphrases Work

Read the accessible comic transcript
- Password confusion: The Business Owner shows a complex password. I.T. Guy notes that remembering it is the real problem.
- Meet entropy: I.T. Guy explains that entropy measures unpredictability. The Business Owner compares it to the growing mess in the office.
- Length and randomness: A predictable short password is compared with six random words. Length plus randomness creates strength.
- Still guessing: A dusty cracking computer estimates 3,500 years. The Business Owner asks whether to wait. I.T. Guy has not cleared his schedule.
The numbers, in plain English
What randomness buys you
Each additional word multiplies the search space by 7,776. The estimate updates when you change the word count above.
| Random words | Entropy | Possible combinations | Worst-case average cracking time |
|---|---|---|---|
| 4 | 51.7 bits | 3,656,158,440,062,976 | About 30 minutes |
| 5 | 64.6 bits | 28,430,288,029,929,701,376 | About 165 days |
| 6 Recommended | 77.5 bits | 221,073,919,720,733,357,899,776 | About 3,500 years |
| 7 | 90.5 bits | 1,719,070,799,748,422,591,028,658,176 | About 27 million years |
| 8 | 103.4 bits | 13,367,494,538,843,734,067,838,845,976,576 | About 212 billion years |
A brief cybersecurity lesson, with pictures
Why Passphrases Work

Read the accessible comic transcript
- Password confusion: The Business Owner shows a complex password. I.T. Guy notes that remembering it is the real problem.
- Meet entropy: I.T. Guy explains that entropy measures unpredictability. The Business Owner compares it to the growing mess in the office.
- Length and randomness: A predictable short password is compared with six random words. Length plus randomness creates strength.
- Still guessing: A dusty cracking computer estimates 3,500 years. The Business Owner asks whether to wait. I.T. Guy has not cleared his schedule.
No cybersecurity degree required
Entropy is the size of the guessing problem.
Imagine hiding one key among ten possible keys. Someone would probably find it quickly. Now imagine hiding it among trillions of keys. The correct key still exists, but finding it becomes considerably more difficult.
A passphrase works the same way. Every randomly selected word increases the number of possible combinations an attacker must try.
The important word is randomly.
Your favorite quotation, a song lyric, your company name, or a sentence about your dog may be long, but attackers know that people use familiar phrases. A secure passphrase uses words selected independently by a cryptographically secure generator.
A deliberately harsh model
Why use such an aggressive estimate?
These figures assume an attacker stole a website's password database, the site used a weak or fast hashing method, and a powerful rig can test one trillion possibilities every second. The estimate also assumes the correct phrase is found after half the possibilities are tested.
Proper password storage can slow an attacker dramatically. You cannot control how every website protects your password, so this educational calculator uses a highly conservative scenario rather than a promise or warranty.
- Stolen password database
- Weak or fast password hashing
- One trillion guesses per second
- Half the search space tested on average
Passphrase versus 16-character password
What Do These Numbers Really Mean?
The estimates below are based on an attacker using powerful equipment capable of making one trillion guesses every second.
That sounds intimidating, and it should. But an attacker still has to identify the correct password from an enormous number of possible combinations. Every additional character or randomly selected word increases those possibilities dramatically.
A short or predictable password might be guessed quickly because attackers do not begin with random combinations. They start with common passwords, names, dates, familiar phrases, and predictable substitutions such as replacing the letter "a" with an "@" symbol.
A long, truly random password or passphrase is different. It can turn an attack that might take hours or days into one requiring thousands, millions, or even billions of years.
Longer is stronger. Random is better. Predictable is dangerous.

16-Character Random Passwords
Same length. Larger character sets.
Random Passphrases
Same 7,776-word list. More random words.
Use your passphrase safely
A strong passphrase protects one account, not every account.
For a password manager's master password, an important computer login, or another sensitive account, use at least six randomly generated words.
- Use a different passphrase for every account.
- Store credentials in a reputable password manager.
- Enable multifactor authentication wherever possible.
- Use passkeys when they are available.
- Never send a passphrase through email or text.
- Never reuse your password manager's master passphrase.
Your passphrase was not saved
Citadel Networks does not know what was generated.
The generator runs locally inside your browser using its cryptographically secure random-number generator. The result is not transmitted to Citadel Networks, included in analytics, or written to server logs.
Once you leave or refresh this page, the displayed passphrase disappears and a fresh one is generated.
How the calculator works
Methodology, Word List, and Sources
For anyone who wants to see where the numbers come from, here is the methodology and the independent security guidance behind this tool.
Words are selected independently and uniformly from the Electronic Frontier Foundation's 7,776-word long list. The generator uses window.crypto.getRandomValues() with rejection sampling to avoid modulo bias. Entropy is calculated as words × log₂(7,776). Crack-time estimates divide the total search space by two and assume one trillion guesses per second.
- Electronic Frontier Foundation: Dice-Generated Passphrases
- NIST SP 800-63B-4: Authentication and Authenticator Management
- OWASP Password Storage Cheat Sheet
EFF website content is available under a Creative Commons Attribution license. Word list source: Electronic Frontier Foundation.
Beyond one credential
A strong passphrase protects one door. A cybersecurity strategy protects the entire business.
Citadel Networks helps business leaders understand their risks, protect critical systems, and make confident cybersecurity decisions.
Schedule a Cybersecurity Briefing