One more random character buys log₂(95) = 6.6 bits. One more Diceware word buys log₂(7776) = 12.9 — nearly twice as much, and you can remember it.
Entropy is a property of the process that generated a password, not of the characters that came out. Five random words is 64.6 bits against 52.6 for eight random characters: about 4,000× harder to guess, and far easier to type from memory. The composition rules everyone was taught — a capital, a digit, a symbol — produced predictable shapes that cracking tools exploit, which is why NIST dropped them.
Only if the words are chosen randomly. Pick them yourself and the entropy collapses, because people do not choose uniformly — they choose a phrase. And none of it survives reuse: a perfect 80-bit password used on two sites is only as strong as the worse-run of the two, because a breach elsewhere hands it over without any guessing at all.
Estimate with the rule, then check it against the calculator that models it properly.
Open Password Strength & Crack Time →One more random character buys log₂(95) = 6.6 bits. One more Diceware word buys log₂(7776) = 12.9 — nearly twice as much, and you can remember it. Entropy is a property of the process that generated a password, not of the characters that came out.