(Credit: René Ramos; Jakub Krechowicz/Shutterstock.com)
Passwords are everywhere. It's true that passkeys are becoming more widespread, but they're far from universal. You still need to remember dozens or hundreds of passwords. If you use a simple, easy-to-remember password, a malefactor might crack it using a dictionary attack or simply learn it by peeking over your shoulder as you log in. If you carefully memorize a complex password like 2a(&K5xq1S8*7-hO (generated for me just now by my handmade password generator) and then use it on every site, a security breach at one site could expose all of your other accounts. Since remembering a different, strong, and complex password for every site is just not possible, what can you do? Try this trick of using passphrases instead of plain old passwords, that's what.
Turn a Sentence Into a Secure, Memorable Password
One way to create a password you can remember is to start with a memorable phrase and boil it down using some simple rules. The phrase "'Do I feel lucky?' Well, do ya, punk?" could become 'DIfl?'W,dy,p?. Or you might take a word you can remember and replace letters with leetspeak equivalents.
The wags who write the xkcd webcomic ridiculed the latter approach, advising that you instead combine random common words to get a long password like CorrectHorseBatteryStaple, and then come up with a story that links those words. "Long password" is the key concept here—the longer the password, the tougher it is to crack. Instead of boiling down a memorable phrase, consider using the phrase in its entirety.
How to Create a Passphrase
A passphrase is simply a phrase or sentence that you use instead of a word or set of characters. Most password systems don't allow the space character, so you'll typically capitalize the first letter of each word instead or insert a punctuation mark, such as a dash between words. The key to creating a strong passphrase for a given website is to use something meaningful to you that wouldn't be easily guessed.
Suppose you want to create a passphrase for the Bank of America website. If you have a historical bent, you might use something like A.P.GianinniFoundedTheBankOfItalyIn1904. That's plenty strong; it has uppercase and lowercase letters, digits, and special characters. Did you notice my sly tweak? I tend to misspell Giannini, so even if clever hackers somehow guessed my passphrase, that misspelling might throw them off.
Maybe your association is the sculpture nicknamed "The Banker's Heart" outside what used to be the Bank of America Center in San Francisco. OK, how about TheBanker'sHeart@555CaliforniaStreet as a passphrase? The point is to use a phrase describing something that you associate with the site, and to use as lengthy a phrase as you can bear to type.
As I mentioned earlier, the strongest password in the world isn't secure if you use it for every one of your secure sites. You do need to come up with a different one for each site. Maybe you regularly use PayPal to pay the kid down the block for mowing your lawn. Your PayPal password could be something like KeepItTrimmed,Kid,AndI'llGiveYou$$. See? It's not so hard.
When Passphrases Don't Fit
Occasionally, you'll find a site whose password length limit makes it tough to use a passphrase. In that case, you might consider boiling the passphrase down to the first letter of each word, retaining any digits or special characters. And, of course, you still have to stay alert to phishing sites. If the page looks like PayPal but the Address Bar shows www.pyapal.gotcha.ru or some such, get out of there fast! The strength of your password is irrelevant if you give it away to fraudsters by entering it at a phishing site.
For an accomplished typist, typing in a passphrase on the keyboard is almost effortless. However, entering that same passphrase on a smartphone or tablet will be supremely difficult. One possible solution is to install a cross-device password manager and use a passphrase as your master password to unlock all your other passwords.
There are many paths to password perfection. Some may prefer to rely on a password manager to generate and manage strong passwords. For others, the passphrase solution offers a dandy balance: easy to remember and tough to crack.


