Normally in Java this is bad practice, reasons are explained, for example, [here](https://stackoverflow.com/questions/8881291/why-is-char-preferred-over-string-for-passwords), but I can see everywhere in the application passphrase is String.