One more random character buys log₂(95) = 6.6 bits. One more Diceware word buys log₂(7776) = 12.9 — nearly twice as much, and you can remember it.
Entropy is a property of the process that generated a password, not of the characters that came out. Five random words is 64.6 bits against 52.6 for eight random characters: about 4,000× harder to guess, and far easier to type from memory. The composition rules everyone was taught — a capital, a digit, a symbol — produced predictable shapes that cracking tools exploit, which is why NIST dropped them.
Only if the words are chosen randomly. Pick them yourself and the entropy collapses, because people do not choose uniformly — they choose a phrase. And none of it survives reuse: a perfect 80-bit password used on two sites is only as strong as the worse-run of the two, because a breach elsewhere hands it over without any guessing at all.
At 95 the rule says 2 and the exact answer is 1.967 — 1.7% high. It holds to within 5% above 70.6, and drifts below it.
A Diceware word is 12.9 bits and a character from the full printable set is 6.6, so the trade really is about two to one — for that character set. Restrict the alphabet and the exchange rate moves against you fast: against lowercase letters alone one word is worth nearly three characters, because each character is now worth only 4.7 bits.
The rule against the exact answer, computed across the range. Inside the shaded band the shortcut is close enough to use; outside it, reach for the calculator.
Estimate with the rule, then check it against the calculator that models it properly.
Open Password Strength & Crack Time →One more random character buys log₂(95) = 6.6 bits. One more Diceware word buys log₂(7776) = 12.9 — nearly twice as much, and you can remember it. Entropy is a property of the process that generated a password, not of the characters that came out.