Text & everyday tools · Password Generator
Diceware, 1995: how a dice-rolling method for passphrases came about
· Background
passwords passphrases provenance
Tells the story of Arnold Reinhold's 1995 diceware proposal — why physical dice, why 7,776 words, why the method spread among cryptographers before reaching the mainstream — and how browser tools inherit it.
A method from the age of PGP — the mid-1990s problem of choosing a strong passphrase for encryption software
The workbook supplies dates, people and a narrative from encryption software to mainstream use, but those historical claims are not proven by the Password Generator implementation. The repository does record a precise software provenance: a browser-native port from xkcdpass 1.30.0 at a named commit, with copyright, licence and omitted command-line features.
This correction produces a narrower but auditable article. It does not deny the broader history; it declines to reconstruct it without primary sources. Readers can follow the port record, current modules and redistributed assets directly instead of treating an outline as archival evidence.
The repository records an xkcdpass port, not a complete history of Diceware
Physical dice can provide observable indexed outcomes, but motives such as tamper resistance and historical appeal need contemporaneous documentation. No such archive is among this module’s sources. ToolAcre itself does not ask the reader to roll dice and cannot validate a physical rolling procedure.
The useful present-day parallel is mathematical rather than historical: a fixed-size list needs a uniform index for each word. Browser bytes can supply that index when they are reduced without bias. The implementation proves this current mechanism; it does not prove why earlier authors made their choices.
Physical-dice motivations are historical claims outside the supplied sources
ToolAcre ships three EFF files, not a preserved original Diceware vocabulary. The long asset has 7,776 verified entries, and the two short assets have 1,296 each. Claims about odd tokens or what later lists removed require comparing source editions under their own licences and records, which this article does not attempt.
The current words are inspectable as committed lowercase text. Credits state that dice columns were removed while words and order remained unchanged. That is the transformation this repository can support, so it is the one documented here.
The shipped EFF files, not the original Diceware vocabulary, are verifiable here
Mailing-list spread, FAQ influence and adoption by security communities are historical topics with no cited archive in the tool source. Adding a confident chronology from memory would violate the authoring contract. This section therefore records the omission explicitly rather than filling space with unsourced reputation claims.
Software provenance is different. The package barrel names the upstream version and commit and lists unported pieces such as argparse, stdin, stdout and interactive mode. A reviewer can compare those artifacts directly, making the claim reproducible.
Community-adoption history is omitted without cited archival sources
EFF attribution, licence and word-file provenance are recorded in the repository’s third-party documents and rendered credits. The interface labels the three lists and the build verifies their sizes. Those facts establish what assets are used today.
They do not establish every editorial criterion, dataset or human review step behind the lists. Such context should be cited from EFF material in a future sourced history. ToolAcre’s calculation needs the current eligible count and uniform selection, not a reconstructed narrative about every word.
EFF provenance is recorded; editorial history is not
The browser path begins when `getRandomValues` fills a typed array. `secureRandomInt` selects the smallest necessary byte width, rejects the incomplete tail and returns an integer below the current pool length. `secureRandomChoice` uses that index for each word independently, and the generator joins results under the chosen formatting rules.
What changed from a physical procedure is the source and reduction implementation. What remains is the requirement for a uniform index into a known list. ToolAcre refuses generation if Web Crypto is unavailable and exposes no deterministic production seed.
From dice-like indices to getRandomValues: the code path that is actually present
Entropy arithmetic is covered by the engine and a separate published article. This history-focused brief does not repeat bit targets or declare a number of words safe for every purpose. The formula remains available from actual list size and independent draw count whenever a reader needs to audit settings.
Separating topics also prevents provenance from becoming security endorsement. A faithful port can still run on a compromised device, and a correctly generated credential can still be phished or reused. Lineage documents implementation; it does not certify the entire operating environment.
The takeaway — the Password Generator is diceware without the dice: the same method, the EFF words, run in your browser
The defensible statement is that ToolAcre ports a documented xkcdpass algorithm surface, redistributes attributed EFF word assets and replaces physical indexing with browser cryptographic draws reduced by rejection sampling. Each part has a repository path.
A complete social history of Diceware needs archival sources beyond this codebase. Until those are verified, keep the article grounded in provenance that can be inspected. Then use the generator only for a fresh private value, never a historical example or reused credential.