The most popular and comprehensive Open Source ECM platform
Security: Passphrases Versus Passwords
Security professionals suggest users begin to adopt passphrases instead of using passwords. What’s the difference? The difference is in length. The longer the security credential, the more secure it is. Research has found that making secure passwords secure with complex rules for case, alphanumerics and special characters are less secure than longer passphrases composed of common words.
You may have missed it, but earlier this year on May 6th (World Password Day), the FBI, based on studies from the National Institute of Standards and Technology (NIST), recommended that users adopt passphrases over passwords.
The FBI said that “instead of using a short, complex password that is hard to remember, consider using a longer passphrase. This involves combining multiple words into a long string of at least 15 characters. The extra length of a passphrase makes it harder to crack while also making it easier for you to remember.”
Roberto Dillon, academic head at James Cook University, said that “our results confirm that the tougher the constraints of creating the passwords the safer users feel with their information. However, the results show that a large number of restrictions can frustrate users. Websites often require passwords that include a combination of special characters, numbers, upper- and lower-case letters, and more. This makes passwords less likely to be compromised by hackers, but harder for users to invent a password and to remember it.”
Reasons to prefer passphrases over passwords include:
- Passphrases are easier to remember.
- Passwords are shorter and easier for hackers to crack.
- Passphrases can incorporate rules, like punctuation and cases, in a natural way that is easy to remember.
- All major Operating Systems like Windows, Linux and Mac support passphrases up to 127 characters
- Passphrases are significantly harder to crack compared to password.














