Diceware Passphrase
Generate Diceware passphrases from the EFF Long word list. Entropy is shown for each passphrase.
Generate Diceware passphrases from the EFF word list. Strong, memorable, mathematically-verifiable entropy. Read more Show less
What is Diceware?
Diceware is a method for generating passphrases that are both strong and memorable. Instead of asking a human to invent a password - which reliably produces something guessable - it picks words at random from a fixed list and joins them together. A five-word Diceware passphrase is roughly as strong as a twelve-character random password, and it is much easier to remember and type.
The method was published by Arnold Reinhold in 1995. The original design uses five six-sided dice: each roll produces a five-digit number from 11111 to 66666, which indexes one of 7776 words. The number of possible passphrases for N words is 7776^N, which gives log2(7776) = 12.9 bits of entropy per word.
How to use
Set the number of words and click Generate. Every change to a setting generates a new passphrase. The output shows the passphrase, its approximate entropy in bits, and the source of the word list.
The default word list is the EFF Long Word List, published by the Electronic Frontier Foundation in 2016 as a drop-in replacement for the original Diceware list. It uses the same 7776-word size but replaces many of the harder-to-spell or obscure words with more familiar ones, and it adds a number of common short words to make passphrases easier to remember.
How much entropy do I need?
Each word from the EFF list contributes 12.9 bits of entropy. Multiply by the number of words:
- 3 words - 38.8 bits. Adequate for a low-value login you do not care about.
- 4 words - 51.7 bits. Acceptable for most online accounts if you also use rate limiting and two-factor auth.
- 5 words - 64.6 bits. Solid baseline. Comparable to a strong random 12-character password.
- 6 words - 77.5 bits. Good margin. Recommended for anything you want to keep for years.
- 7+ words - 90+ bits. For long-lived master passwords, disk encryption, or private keys.
The entropy estimate assumes the words are chosen uniformly at random from the full list, with no reuse, and that the attacker knows the method and the list. Diceware depends on that assumption - the strength comes from the randomness, not from the words being secret.
Why passphrases beat passwords
Humans are bad at randomness. When asked to invent a password, most people produce something that follows predictable patterns: a common word, a year, a capital letter at the start, a digit or symbol at the end. Every one of those patterns reduces the search space and every one of them has been exploited by real attackers.
Diceware sidesteps the problem entirely by removing the human from the randomness step. The words are selected uniformly from a list that the user cannot bias. The result is a passphrase whose entropy is mathematically known rather than guessed at.
The trade-off is length. A five-word Diceware passphrase is around 30-40 characters, which is longer than most people are used to typing. That is the point - it is easier to remember than a random string of the same entropy, even though it is longer.
What Diceware is not
Diceware generates a passphrase; it does not store it, manage it, or use it. Anything you generate here is shown once and never sent anywhere. If you lose it, there is no recovery - that is a property, not a bug.
A Diceware passphrase does not replace a password manager. For accounts you use frequently, a password manager with a strong master passphrase (which could be a Diceware passphrase) is generally better than trying to remember many different Diceware passphrases.
FAQ
Is a Diceware passphrase as strong as a random password?
For the same entropy, yes. Five Diceware words is 64.6 bits, roughly equivalent to an 11-character random password from a 64-character alphabet (11 x 6 = 66 bits). The Diceware passphrase is much easier to remember and type.
Why 7776 words?
Because 6^5 = 7776, and five six-sided dice produce exactly 7776 equally likely outcomes. This lets a user generate passphrases with physical dice and a printed word list, with no computer and no bias.
Can I use my own word list?
Yes, in principle, but the security depends on the list being large and the selection being uniform. A list of a few hundred common words gives far less entropy per word and is not recommended.
What is the difference between EFF Long, EFF Short, and original Diceware?
The original Diceware list (1995) is the classical one. The EFF Long list (2016) is 7776 words chosen for memorability. The EFF Short list is a 1296-word subset that trades entropy for shorter passphrases. This tool uses the EFF Long list.
Should I capitalize words or add symbols?
Not for security. Adding predictable punctuation does not increase entropy in any meaningful way and makes the passphrase harder to remember. If you want more security, add another word - it contributes 12.9 bits, which is far more than any punctuation scheme.
Can the browser generate truly random words?
Yes. This tool uses crypto.getRandomValues, which is the browser's cryptographically secure random number generator. It is the same source used for TLS keys and cryptographic nonces, and it is not the same as Math.random.
Command line equivalent
# Python (diceware library)
pip install diceware
diceware
# Python (manual, using EFF wordlist)
python3 -c 'import secrets; words=[l.split()[1] for l in open("eff_large_wordlist.txt")]; print(" ".join(secrets.choice(words) for _ in range(6)))'
# Bash + shuf
shuf -n 6 /path/to/eff-large-wordlist.txt | awk '{print $2}' | tr "\n" " "
# Node
node -e 'const fs=require("fs"); const w=fs.readFileSync("eff_large_wordlist.txt","utf8").split("\n").map(l=>l.split("\t")[1]).filter(Boolean); const r=crypto.randomBytes(6); console.log(Array.from({length:6},(_,i)=>w[r[i]%w.length]).join(" "))'