Essential cookies only — Cookie Policy.

Security Fundamentals

Why Passphrase Length Beats Character Complexity

📅 9 Apr 2026·⏱ 7 min·✍ Daniel Hayes

The history of password policy is largely a history of misplaced priorities. Complexity requirements — uppercase, lowercase, number, symbol — became standard because they appeared to increase entropy. In practice, they increased friction while providing limited security, because they were applied to human-chosen passwords where the theoretical entropy was never achieved. Length requirements, applied to randomly generated credentials, provide exactly the entropy promised. Understanding why explains the shift from complexity to length in NIST, NCSC, and most major security frameworks from 2017 onwards.

The Complexity Myth

A password satisfying typical complexity requirements (8+ chars, upper, lower, digit, symbol) from a human-chosen base word has approximately 52 theoretical bits of entropy. In practice, the real entropy is far lower — because humans apply complexity rules predictably. Research by Weir et al. (2010) demonstrated that users facing complexity requirements produce highly predictable patterns that reduce cracking time by orders of magnitude compared to uniformly random selection.

NIST SP 800-63B (2017) concluded: "Composition rules are no longer recommended." The NCSC echoed this in 2016 and reiterated it in every subsequent update. The fundamental insight: complexity rules applied to human-chosen passwords provide false confidence without proportionate security benefit.

What Length Actually Provides

Length, applied to randomly generated credentials, provides exactly the entropy it promises — because the character or word positions are selected uniformly at random from the available set. Every additional character in a random password adds the same entropy regardless of what came before. The multiplier is precise and reliable.

Length / WordsEntropyTime to crack at 10B/sec
8 random chars52.4 bits~13 hours
12 random chars78.7 bits~9.6 million years
3 random words38.7 bits~7 minutes
4 random words51.6 bits~3.6 days
5 random words64.5 bits~2,900 years
6 random words77.4 bits~2.2 million years

The Practical Conclusion

For any memorisable credential: 5 words is the minimum for strong security; 6 words for encryption keys and master passwords. For stored credentials (in a password manager): 20+ random characters is optimal. In both cases, the answer is "longer" — not "more complex". The Passphrase Maker defaults to 4 words and shows the entropy calculation for any configuration, making the security implications of each choice visible at generation time.

NIST SP 800-63B 2025: "Password length has been found to be a primary factor in characterising password strength... verifiers SHOULD allow passwords at least 64 characters in length." Minimum 15 characters. No mandatory complexity. Breach database checking required. Length wins.
password length entropy complexity NIST passphrase security
For informational purposes only. Password security requirements vary by context — consult your organisation's security policy and current NCSC/NIST guidance for your specific environment.

⚡ Try NordPassGet NordPass at 56% off + 3 months extra and experience enterprise-grade password security at an affordable price. Features include zero-knowledge encryption, cross-platform sync, and breach monitoring.