A strong passphrase can be long enough to resist guessing while still being practical to remember.
In this lesson you will build a practice passphrase from unrelated words, test it for common weaknesses and improve it.
Important: do not create or share a real account password during this exercise. Use only practice examples.
What you will learn
By the end of this lesson, you should be able to create a long and memorable practice passphrase using unrelated words and explain why it is stronger than a short or predictable password.
Before you start
You should already understand the main ideas from How Strong Passwords and Passphrases Work.
You need only a piece of paper or a private temporary note for this exercise.
Do not write down an existing password. Do not use the practice phrase for a real account.
Step 1: Understand the goal
A passphrase is a password made from several words or pieces of text.
The goal is not to create a sentence that sounds clever. The goal is to create something long and difficult for another person or guessing program to predict.
For this lesson, we will use these rules:
- Use unrelated words.
- Avoid personal information.
- Avoid famous phrases and quotations.
- Aim for at least 16 characters.
- Make the practice phrase unique.
These are practical learning rules. A website may have its own password requirements.
Step 2: Choose unrelated word categories
Start by choosing several categories that have little connection with one another.
For example:
- A place
- A plant
- An object
- A food
You could choose completely different categories if you prefer.
The purpose of using separate categories is to reduce the chance that your words naturally form a common phrase.
Step 3: Pick one random practice word from each category
Imagine that the following words were selected:
- harbor
- cactus
- lantern
- mango
They do not tell a story and they do not describe one person.
A simple practice passphrase could therefore be:
harbor cactus lantern mango
Do not use this example for a real account. It is published here, so it is not secret.
Step 4: Check the length
Length is one of the most important characteristics of password strength.
Current NIST guidance requires at least 15 characters when a password is the only authentication factor. CISA gives consumers a simple target of at least 16 characters.
For this exercise, aim for at least 16 characters.
The example is comfortably longer than that.
If your practice phrase is too short, do not simply add a predictable number such as 123.
Add another unrelated word instead.
Step 5: Check for personal information
Now ask whether someone who knows you could guess any of your words.
Weak choices can include:
- Your name
- Your child's name
- Your pet's name
- Your birthday
- Your school or workplace
- Your favourite sports team
- Your home town
Information like this may be known by friends, relatives or colleagues. Some of it may also be visible on social media.
If one of your practice words is closely connected to you, replace it with something unrelated.
Step 6: Check whether the words form a common phrase
Several words do not automatically make a good passphrase.
A famous quotation, song lyric, movie line, proverb or familiar expression can be predictable.
For example, using a well known sentence as a password may create plenty of characters, but an attacker can test common quotations and phrases.
Random relationships between words are more useful.
Step 7: Do not depend on obvious substitutions
Changing a letter to a similar number or symbol may make a password look more complicated without making it much less predictable.
Examples include replacing the letter o with zero or replacing the letter a with a symbol.
Attackers know these common patterns.
If a website requires a symbol, number or capital letter, follow that requirement. Just do not depend on predictable substitutions as your main source of strength.
Step 8: Test a weak example
Consider this practice example:
SakiyaColombo2026
It is reasonably long, but it could still be weak for someone named Sakiya who lives in Colombo.
Why?
- It contains personal information.
- It uses a predictable year.
- Its structure is easy to understand.
Length alone does not make predictable information random.
Step 9: Improve the weak example
Instead of modifying the personal information, start again with unrelated words.
For example:
velvet forest kettle comet
Again, never use this published example as a real password.
The important improvement is not the specific words. It is the fact that the phrase no longer depends on information about a person.
Step 10: Decide whether you really need to remember it
You do not need to create memorable passphrases for every account.
A password manager can generate and store long random passwords for ordinary accounts.
This is often better than trying to memorize dozens of passwords.
A memorable passphrase can be especially useful for a small number of important secrets that you genuinely need to remember, such as the main password used to unlock a password manager.
Practice activity
Create three practice passphrases. Do not use real personal information and do not reuse them as real passwords.
Practice phrase 1
Choose four unrelated words.
Check:
- Is it at least 16 characters?
- Are the words unrelated?
- Is personal information absent?
- Is it different from a famous phrase?
Practice phrase 2
Create another example using completely different word categories.
Try to make it memorable without turning it into a predictable sentence.
Practice phrase 3
Create one intentionally weak example using personal or predictable information.
Then identify exactly what makes it weak and replace those parts with unrelated words.
Self check
Answer these questions before finishing.
- Why is length useful for password strength?
- Why should the words in a passphrase be unrelated?
- Why is a birthday a poor ingredient for a password?
- Why should famous quotations be avoided?
- When might a password manager be better than memorizing another passphrase?
Suggested answers
- Longer passwords create more possibilities for an attacker to guess.
- Unrelated words are less predictable than familiar combinations.
- A birthday may be known or discovered by another person.
- Famous quotations may already appear in password guessing lists.
- A password manager can generate and store a unique random password that you do not need to remember.
Before using a real passphrase
When you later create a real passphrase, do it privately.
Do not copy any example published in this lesson.
Do not reuse a passphrase from another account.
Do not send your passphrase to another person for checking.
If you use a password manager, let it generate random passwords for accounts that you do not need to memorize.
Turn on multi factor authentication where available so that a password is not your only layer of protection.
Lesson summary
A useful memorable passphrase should be long, unique and difficult to predict.
Unrelated words can help you create length without relying on complicated character tricks.
The most important habits are:
- Use unrelated words.
- Avoid personal information.
- Avoid common phrases.
- Aim for plenty of length.
- Use a different secret for every account.
- Use a password manager when appropriate.
Continue learning
Review the concepts in How Strong Passwords and Passphrases Work.
For the wider online safety framework, read Complete Guide to Staying Safe Online.