Forum Discussion
Former Member
4 years ago@300troop I think the NCSC's message is aimed at people who are not using a password manager. The argument for using passphrases built of dictionary words is that they are secure enough and more memorable than a purely random password. Generally speaking, people using a password manager don't need to remember passwords and so should use purely random passwords as they are more secure. The exception, I think, is where you might need to say a password over the phone or enter it into an app on an unsupported platform, e.g. a TV. In this case, it makes sense to use passphrases or passwords with easy to read patterns.