English

Text & everyday tools · Password Generator

How diceware passphrases work: five dice, 7,776 words, 12.9 bits each

· How it works

passwords passphrases cryptography

Five dice selecting one indexed word and six independent words forming a passphrase
Original ToolAcre vector illustration

Explains the diceware method — roll five dice, look up one of 7,776 words, repeat — and why each word adds a fixed, calculable amount of strength regardless of which word came up.

The password on the sticky note — why memorable and strong usually pull in opposite directions, and how diceware resolves it

A sticky-note password is memorable partly because its owner chose it; that choice is exactly what an attacker predicts. A Diceware-style passphrase instead chooses ordinary words at random from a fixed list. It can be easier to type and rehearse than a short string of symbols while deriving its strength from the number of independent possibilities. “Memorable” does not mean that you may rearrange or replace the randomly chosen words until the phrase sounds personal.

Five dice, one word — how 6⁵ = 7,776 outcomes map onto a numbered wordlist

Five fair six-sided dice have 6×6×6×6×6 = 7,776 ordered outcomes. A traditional numbered Diceware list maps each five-digit dice result to one word, so a roll such as 12345 selects the word at that entry—not a word the user likes. Repeat the five-roll process for every additional word. An EFF list of the same size can also be indexed by a secure computer-generated integer rather than physical dice; the indexing method differs while the count of equally likely outcomes stays the same.

Why every word is worth the same — about 12.9 bits per word, whether it is 'zebra' or 'the', because the choice was uniform

If every one of the 7,776 words is equally likely on an independent draw, the uncertainty per word is log₂(7,776) ≈ 12.925 bits. “Zebra” has no more entropy than “the” when both are chosen uniformly; a person preferentially choosing one over the other changes the distribution. ToolAcre’s generator selects words with replacement, which means a repeated word is possible and should not be edited away merely because it looks odd. The cryptographic random-source implementation avoids modulo bias by rejecting out-of-range draws.

Adding words — how six words reach roughly 77 bits and what each extra word buys

Six independent long-list words have 7,776⁶ possible sequences and about 6×12.925 = 77.55 bits of ideal search space. Five words offer about 64.62 bits, while an extra seventh word adds another 12.925. This is not a promise that an online service cannot be attacked by phishing or malware; it is arithmetic for an offline guessing model with a known list and uniform selection. A reused passphrase can fail when one service is breached regardless of how many bits it had when generated.

Dice versus a browser — how a cryptographic random number generator replaces physical dice without changing the maths

ToolAcre does not ask you to roll physical dice. Its secureRandomInt obtains browser Web Crypto bytes and uses rejection sampling to pick a uniformly distributed word index; Math.random is not a fallback. The computation still assumes an honest device, browser, and source file for the wordlist. A computer running malicious extensions or a compromised clipboard can expose a generated secret even when the website has no server receiving it. The Password Generator’s own pages exclude third-party ad and analytics scripts because the generated value is a credential in the DOM.

Worked example — generating a six-word passphrase and calculating its entropy by hand from the wordlist size

For a six-word example, do not copy a phrase somebody else printed in an article: it would already be public. Instead press Generate six words from the 7,776-entry EFF long list. Regardless of the particular output, the ideal entropy calculation is log₂(7,776⁶) ≈ 77.55 bits. Check the UI’s displayed estimate and save the fresh phrase in a reputable password manager. If you insist that one specific word appear, the list of possible outputs shrinks and the calculation must change.

What this does not cover — choosing your own words, which breaks the uniformity assumption, and site-specific password rules

This model does not apply to words you picked yourself, a quotation you can remember, or a list shortened by excluding difficult words unless you recalculate its size. It does not override website-specific maximum lengths, rate limits, account recovery vulnerabilities or the risk of entering secrets into a device you do not trust. A random phrase is not a substitute for multi-factor authentication or a password manager that generates a different secret per account.

The takeaway — the Password Generator applies the diceware method with the EFF wordlists and a cryptographic generator, entirely in your browser

Five dice encode one uniformly chosen list index; a secure browser generator can choose the same index without physical dice. The Password Generator implements that choice with EFF wordlists and Web Crypto locally. The next useful step is not memorising the formula: it is creating a fresh passphrase, checking the estimate and never reusing that exact result on another account.