Password advice splits into two camps: memorize a few long passphrases, or generate random strings and store them in a manager. Both beat reusing Summer2024! everywhere — but they protect against different threats, and the best answer is usually both.

The case for passphrases

A passphrase like correct-horse-battery-staple gets its strength from length. Four random words from a ~7,700-word list give about 51 bits of entropy — far beyond what brute force can touch, yet genuinely memorable. Passphrases shine where you must type from memory: your device unlock, your password manager's master password, disk encryption.

Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →

Their weakness is reuse pressure. Humans can reliably memorize a handful of passphrases, not a hundred. The moment one passphrase protects multiple accounts, a single breach cascades.

The case for password managers

A manager removes the memorization bottleneck entirely: every account gets a unique 20+ character random string, and you remember one master passphrase. Unique-per-site passwords mean a breach at one service is contained — the stolen credential works nowhere else.

Managers add a second defense people underestimate: they only autofill on the correct domain, so a pixel-perfect phishing page gets nothing. Your memory can't do that check; the manager does it automatically.

How they compare

  • Brute force: both win easily, if the passphrase is truly random (use a generator, not your brain — try the passphrase generator or the password generator).
  • Breach containment: managers win decisively through uniqueness.
  • Phishing: managers win through domain-bound autofill.
  • Availability: passphrases win — no software, no sync, no master file to lose. A manager needs backups of its vault.

The practical setup

Use a manager for the hundred accounts you can't memorize, locked behind one strong memorized passphrase. Check any password you're unsure about with the password strength analyzer. And enable two-factor authentication on the accounts that matter most — because even the best password is only one factor.