Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Passphrase Generator (Diceware)

Memorable random passphrases from the EFF word lists — or from your own dice.

Security No upload Works offline Free, no sign-up

Passphrase

—

—

    Options

    Word lists by Joseph Bonneau for the Electronic Frontier Foundation, used under CC BY 4.0.

    Generate several

    Set a number above 1 to make a list (up to 50), one passphrase per line.

    Next steps

    About the Passphrase Generator (Diceware)

    A passphrase is a handful of randomly chosen words — easy to remember and type, and very hard to guess. This generator follows the Diceware method (Arnold Reinhold, 1995) with the Electronic Frontier Foundation's word lists: the EFF Large Wordlist (7,776 words, 12.9 bits each) and the two EFF Short Wordlists (1,296 words, 10.3 bits each). Six words from the large list give about 77.5 bits of entropy, the strength EFF recommends for most uses.

    Words are picked with your browser's cryptographically secure random generator, with rejection sampling so that every word is exactly equally likely. Choose the number of words, the separator, capitalisation and an optional digit or symbol; the entropy shown counts exactly what each option adds. Prefer not to trust any software? Switch to Use my dice, roll real dice and type the numbers — the words are looked up on your device, and you can check them against the printed list. Nothing is stored or sent.

    How to use it

    1. Choose a word list: EFF Large (default) or a Short list, whose words are quicker to type but add fewer bits each.
    2. Set the number of words — EFF recommends at least 6 from the large list; 8 from a short list are about as strong — and the separator.
    3. Only if a site insists on capitals, digits or symbols, add them under Capitalisation and Add. More words add far more strength.
    4. Copy the passphrase, or press New passphrase for another. Use How many to make a list to choose from.
    5. For a passphrase made with physical dice, choose Use my dice, roll five dice per word (four for a short list) and type the numbers.

    Examples

    Six words, EFF Large Wordlist
    Result
    arrest-stumble-automaker-renewably-skinny-igloo

    6 × log₂(7,776) ≈ 77.5 bits. An example of the format — never use a passphrase you have seen published, including this one.

    Eight words, EFF Short Wordlist #1
    Result
    step xerox bud robin elk thing skew dose

    8 × log₂(1,296) ≈ 82.7 bits from short, quick-to-type words. An example — generate your own.

    Dice rolls turned into words
    Input
    43526 16655 66666 11111 25134 31462
    Result
    paragraph contusion zoom abacus elude freight

    Each group of five dice is a line of the EFF Large Wordlist: 11111 is the first word (abacus), 66666 the last (zoom).

    Common uses

    • A master password for a password manager such as Bitwarden, KeePassXC or 1Password.
    • Disk and backup encryption passphrases (BitLocker, FileVault, VeraCrypt, LUKS) and SSH or PGP key passphrases.
    • Wi-Fi passwords that guests have to type from a card.
    • Any password you have to remember or type by hand rather than paste from a manager.

    How strong is a passphrase?

    For words picked at random, the strength is exact: bits = words × log₂(list size) — 12.9 bits per word from the large list, 10.3 from a short list. The attacker is assumed to know the list, the number of words and your options, so separators and capitalising every word add nothing; only random choices count.

    • 4 words: 51.7 bits — found in about 2 days on average at 10¹⁰ guesses per second (a stolen database with a fast hash such as SHA-256)
    • 5 words: 64.6 bits — about 45 years at that rate
    • 6 words: 77.5 bits — about 350 thousand years at 10¹⁰ per second, about 350 billion years at 10⁴ per second (a slow, salted hash such as bcrypt)
    • 7 words: 90.5 bits — about 2.7 billion years at 10¹⁰ per second
    • 8 short-list words: 82.7 bits — about 12.6 million years at 10¹⁰ per second

    The two rates are the offline-attack scenarios of the zxcvbn strength estimator (Wheeler, USENIX Security 2016). Six words from the large list are about 47 characters long with separators (7 letters per word on average), far beyond NIST SP 800-63B-4's 15-character minimum for passwords used on their own — but what makes them strong is the number of random words, not the characters.

    Capitals, digits and symbols

    Some sites demand an upper-case letter, a digit or a symbol. Capitalise one random word adds log₂(words) bits (2.6 bits for six words), and a digit or a symbol after a random word adds log₂(10 × words) each (5.9 bits for six words). One more word adds 12.9 bits — so add words for strength, and the extras only to satisfy a site's rules. The symbols are ! # $ % & * + = ? @, chosen so they never clash with a separator; they and the digit always follow a word, which keeps the passphrase uniquely readable and the entropy figure exact.

    Why roll real dice?

    Dice make the randomness independent of any computer: no software, browser extension or hidden flaw can influence or record the result, and anyone can check the words against the printed list. Roll five dice for each word of the large list (four for a short list), decide the reading order (for example left to right) before you look, and type the numbers — "43526 16655", one group per word, or all digits in a row. Each group, read as a base-6 number with 1 standing for 0 and 6 for 5, is a line of the list. Download the list gives you EFF's file with its dice numbers, to print or keep offline.

    About the word lists

    The EFF word lists were made by Joseph Bonneau for the Electronic Frontier Foundation in 2016 (how they were built) and are used here under the CC BY 4.0 licence. The large list has 7,776 recognisable words of 3 to 9 characters (7.0 on average), with profane, difficult-to-spell and homophone words removed, and no word is the start of another — so even a passphrase without separators can only be read one way. Short list #1 has 1,296 words of at most five letters (4.5 on average); short list #2 has longer, more memorable words, each with a unique first three letters and at least three edits away from every other word. The files are bundled unchanged: their SHA-256 checksums match EFF's originals, and they are only downloaded when the generator first needs them.

    Limitations

    • Passphrases are not saved anywhere. Copy yours before you leave or reload the page.
    • Copied passphrases stay on your clipboard (and in any clipboard history) until you copy something else.
    • The word lists are English only.
    • Picking your favourite from many generated passphrases makes it slightly weaker: choosing one of 10 costs at most 3.3 bits.
    • Dice mode is only as random as your rolls: use real dice, roll them properly and do not re-roll a result you dislike.

    Privacy

    Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

    Frequently asked questions

    Is a passphrase better than a random password?

    Per character, a random password is stronger; per thing you have to remember and type, a passphrase wins. Use passphrases for anything you type by hand — a password manager's master password, disk encryption, Wi-Fi — and long random passwords from your manager for everything else.

    How many words should I use?

    EFF recommends at least six words from the large list (about 77.5 bits) for most uses. With a short list, eight words give about the same strength (82.7 bits), as EFF's description of the lists points out. Add one or two words for secrets that protect a lot, such as a password manager or full-disk encryption.

    What is Diceware?

    A method published by Arnold Reinhold in 1995: roll dice to pick words from a numbered list, so the passphrase is truly random but made of real words. EFF's 2016 lists are designed for the same method, with longer, more recognisable words than Reinhold's original list.

    Does a separator or capitalising every word make it stronger?

    No. An attacker tries every format you could have picked, so fixed choices add nothing. Only random choices add strength: more words, or the "one random word", digit and symbol options, whose extra bits are shown.

    Is it safe to generate a passphrase on a website?

    This page generates it in your browser with crypto.getRandomValues, the operating system's secure random generator; nothing is sent or stored, and it works offline after loading. For zero trust in software, use your own dice.

    Why not use "correct horse battery staple"?

    Because everybody knows it: since the famous xkcd comic, that exact phrase is in attackers' lists. A passphrase is only strong if it was chosen at random and has never been published — which is why the examples on this page should not be used either.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.