marclar.tech

Correction: How to Create a Strong Master Password

A correction to my earlier master-password advice, with current guidance for creating a long, random, unique passphrase.

I need to correct the advice that originally appeared here. A movie quote, song lyric, or other familiar phrase with predictable substitutions is not a good master password. Attackers test common phrases and the character swaps people usually make.

Current CISA guidance says passwords should be long, random, and unique. For the one master password you must remember, CISA recommends a passphrase made from 4–7 unrelated words. Use words selected randomly—not a quotation, title, personal fact, or story that someone could connect to you—and make the result at least 16 characters. Do not reuse it anywhere else.

A password manager should generate and store a different random password for every other account. Enable multifactor authentication on the password manager where supported, and store its recovery information offline in a secure place according to the provider's recovery instructions. Never publish or share your real master passphrase.

NIST explains why length and screening against common or compromised passwords matter more than forced mixtures of symbols and capitalization.

The expanded correction is here: A Safer Way to Create a Memorable Master Password.