How To Create an Unguessable Master Password You'll Remember

Affiliate disclosure: This article contains affiliate links. If you click a link and make a purchase, we may earn a commission at no extra cost to you. Our editorial recommendations are never influenced by commissions — read our full disclosure policy.
One Password That Has to Be Right
Adopt a password manager and you have collapsed a hundred problems into one. Every account gets a long random string you never see and never type. The security of all of it now rests on a single phrase in your head.
That is a good trade — but only if the single phrase is genuinely strong, because a vault is exactly as protected as the thing that opens it. This is the one password worth spending half an hour on.
Why the Advice You Were Given Is Wrong
"At least eight characters, with an uppercase letter, a number and a symbol." Everyone has heard it, most systems enforce it, and it produces a predictable result: a common word, capitalised at the front, with a digit and an exclamation mark at the end.
Substituting a zero for an o, a three for an e, an at-sign for an a — these are not obstacles. They are the first transformations every cracking tool applies, because they are the first ones every human thinks of. A composition rule tells an attacker as much about the shape of your password as it tells you.
What actually resists guessing is entropy: how many equally likely possibilities the method you used could have produced. And entropy comes overwhelmingly from length and from genuine randomness, not from character variety.
The uncomfortable corollary is that you cannot choose randomly. A word that occurs to you occurred to you for a reason, and the reasons are shared. This is not a failure of imagination; it is how minds work. Randomness has to come from outside your head.
The Passphrase Method
A passphrase is a sequence of words chosen at random — not a sentence you composed, not a theme, not a memorable phrase from a song. Random words, strung together.
It is longer than a password, which is where the strength comes from. And it is made of real words, which is where the memorability comes from. Those two properties usually trade against each other and here they do not, which is the whole reason the method has lasted.
The critical word is random. Five words you picked yourself, about things you like, is not a passphrase. It is a sentence, and sentences are guessable.
Diceware, at the Source
The best-documented way to get randomness from outside your head is the Electronic Frontier Foundation's dice method, and the details are worth taking from EFF's own page rather than from summaries.
EFF's long wordlist contains 7,776 words, which is 6 to the power of 5 — one word for every outcome of rolling five dice. So the procedure is exactly that: roll five dice, read the five-digit result, look up the word.
EFF recommends making a six-word passphrase, and states what that buys: "This passphrase is one of 221073919720733357899776 (or about 2⁷⁷) alternatives that could have been chosen by this method."
That number is the whole argument. It is not a claim about how clever the words look. It is a count of how many equally likely passphrases the method could have produced, and it holds even if an attacker knows exactly which wordlist you used and exactly how many words you took. That is the property a self-chosen phrase can never have.
The mechanics:
- Get five physical dice. Real dice are the point — a random number from a website is a random number from somebody else's computer.
- Roll all five at once and read them left to right as a five-digit number.
- Find that number in EFF's list and write down the word.
- Repeat until you have six words.
- Join them with hyphens or spaces.
What Good and Bad Look Like
| Candidate | Why it is what it is |
|---|---|
| Six words from a 7,776-word list, rolled with dice | Strong. Around 77 bits, and the strength survives the method being public. |
| Four words from the same list | Weaker, and the gap is enormous — each word dropped divides the possibilities by 7,776. |
| Six words you chose because they felt random | Unknowable. The strength depends on how predictable your associations are, and you cannot measure that. |
| A memorable song lyric, capitalised, with a number | Weak. Phrase lists are part of every serious cracking setup. |
| A short string with symbol substitutions | Weak. Substitution is the first thing tried. |
| Your manager's generated random string | Very strong, and unmemorable — which is fine for entries in the vault and wrong for the master. |
That last row matters. The master password is the one credential in your life that must live in your memory rather than in the vault, so it is the one place where memorability is a hard requirement rather than a convenience.
Making It Stick
A six-word passphrase is memorable, but it takes a few days to become automatic. The techniques that work:
- Build one absurd image that contains all six words. Ordinary scenes fade; ridiculous ones do not. The stranger the picture, the more reliable the recall.
- Type it deliberately, ten or fifteen times, on the day you create it. Muscle memory forms faster than you expect and does much of the work afterwards.
- Type it again on each of the next three days, before you need it in anger. Spaced repetition over a few days is what moves it into long-term memory.
- Keep it on paper for the first fortnight, somewhere physically secure — a safe, a locked drawer. Destroy the paper once you have not needed it for a week.
- Do not change it on a schedule. Rotation forces predictable variations. Change it when there is a reason.
The Rules Worth Following Absolutely
- Never store the master password digitally. Not a note, not a file, not an email to yourself, and not in the manager it opens.
- Never reuse it anywhere else, for anything, ever. It is the one credential with no second line of defence.
- Never type it on a device you do not control — a work machine you do not own, a shared family computer, a hotel terminal.
- Never share it, including with family. If someone needs access after your death, use the manager's emergency access feature, which exists precisely so that sharing the master password is unnecessary.
- Do add a second factor to the vault, and keep its recovery codes on paper outside the vault. The reasoning is in 2FA recovery codes explained.
When You Have Forgotten It
Say this plainly, because it is the thing nobody mentions until it happens: in a properly built zero-knowledge system, the provider cannot recover your vault. That is the same property that means their breach is not your breach. It is not a gap in the service, it is the service.
What you get instead is whatever emergency mechanism the provider offers — a recovery key generated at setup, an emergency contact, a recovery code sheet. Whichever it is, set it up on the day you create the account, print it, and store it somewhere other than the computer. The week you forget the passphrase is the week that piece of paper is worth more than the subscription.
The Counter-Argument
A reasonable objection: a six-word diceware passphrase is a lot of ceremony for a threat most people never face, and the realistic risk to a household is not a cracking rig against a stolen vault but phishing and reuse — both of which are solved by adopting a manager at all, whatever the master password looks like.
Largely true, and it is why "any manager with a mediocre master password" still beats "no manager". But the ceremony here is one evening, once, for a credential you will keep for years. The cost is small enough that the argument for cutting the corner is weak even when the risk it addresses is remote.
If you have not chosen a manager yet, the mechanism is explained in what a password manager is and the shortlist is in best password managers 2026.
Covered in this guide
Reviewed by NorwegianSpark Editorial — written with AI assistance and reviewed by the NorwegianSpark SA editorial team · Last updated: 6 September 2026





