Password advice splits into two camps: memorize a few long passphrases, or generate random strings and store them in a manager. Both beat reusing Summer2024! everywhere — but they protect against different threats, and the best answer is usually both.
The case for passphrases
A passphrase like correct-horse-battery-staple gets its strength from length. Four random words from a ~7,700-word list give about 51 bits of entropy — far beyond what brute force can touch, yet genuinely memorable. Passphrases shine where you must type from memory: your device unlock, your password manager's master password, disk encryption.
Related reading: How to Remain Valuable When Intelligence Becomes Cheap — a 224-page practical book on staying valuable as intelligence gets cheap. $3.84. Read it on Gumroad →
Their weakness is reuse pressure. Humans can reliably memorize a handful of passphrases, not a hundred. The moment one passphrase protects multiple accounts, a single breach cascades.
The case for password managers
A manager removes the memorization bottleneck entirely: every account gets a unique 20+ character random string, and you remember one master passphrase. Unique-per-site passwords mean a breach at one service is contained — the stolen credential works nowhere else.
Managers add a second defense people underestimate: they only autofill on the correct domain, so a pixel-perfect phishing page gets nothing. Your memory can't do that check; the manager does it automatically.
How they compare
- Brute force: both win easily, if the passphrase is truly random (use a generator, not your brain — try the passphrase generator or the password generator).
- Breach containment: managers win decisively through uniqueness.
- Phishing: managers win through domain-bound autofill.
- Availability: passphrases win — no software, no sync, no master file to lose. A manager needs backups of its vault.
The practical setup
Use a manager for the hundred accounts you can't memorize, locked behind one strong memorized passphrase. Check any password you're unsure about with the password strength analyzer. And enable two-factor authentication on the accounts that matter most — because even the best password is only one factor.