"Use a strong password" advice usually means longer strings of random letters, numbers, and symbols — which are also famously hard to remember. Diceware takes a different approach: instead of random characters, it strings together random real words, trading a bit of length for something a person can actually memorize.
What Diceware Actually Is
Diceware is a method for generating a passphrase by rolling physical dice to pick words at random from a numbered word list — the dice rolls translate into a lookup number, and that number maps to one word. The word choice is the important part: because each word is picked completely at random from a fixed list, and the list itself is public, the security of the resulting passphrase can be mathematically calculated rather than just assumed. The technique predates its digital implementations, but the core idea — random selection from a known, finite list — is exactly what a browser-based passphrase generator automates using cryptographically secure randomness instead of dice.
Why a Specifically Designed Word List
Not just any dictionary works well for this. The word list needs three properties: every word should be easy to spell correctly from memory, words shouldn't be easily confused with each other (which would make transcribing the passphrase error-prone), and the list should avoid offensive terms since it's public infrastructure anyone might use. The Electronic Frontier Foundation built a word list specifically with these constraints in mind, sized at exactly 1,296 words — 6 to the 4th power — a number chosen so the math of random selection from it stays clean and easy to verify.
How to Calculate Entropy Yourself
Entropy — a measure of how many equally likely possibilities there are — is calculated as log base 2 of the number of choices. For a 1,296-word list, that's log₂(1,296) ≈ 10.3 bits of entropy per word. Since each word is chosen independently, entropy adds up directly across words: a 4-word passphrase has about 41 bits, a 6-word passphrase has about 62 bits, and an 8-word passphrase has about 82 bits. Doubling the word count doesn't just double the security — it multiplies the total number of possible passphrases, since each added word multiplies (not adds to) the count of combinations.
Passphrase vs. Password: Which Wins
A common myth is that a short random-character password is automatically stronger than a longer passphrase because it "looks more random." In practice, entropy is what determines resistance to guessing, not visual complexity. A typical 8-character random password drawn from roughly 95 printable characters carries about 52 bits of entropy — noticeably less than a 6-word Diceware passphrase's roughly 62 bits, while being considerably harder for a person to memorize and type correctly.
Generating One Instantly
Generate a fresh Diceware-style passphrase using the real EFF word list and cryptographically secure randomness with the free Passphrase Generator — adjust the word count and watch the entropy meter update live.
FAQ
What is Diceware, and why use a word list instead of random characters? Diceware is a method (originally using physical dice) for generating passphrases by picking random words from a fixed list. A multi-word passphrase like "correct horse battery staple" can be both easier to remember and have more actual entropy than a shorter string of random characters, since each additional word multiplies the number of possible combinations.
Why does this use the EFF's specific word list instead of just any dictionary? The Electronic Frontier Foundation's word list was deliberately designed for this purpose — it avoids offensive terms, avoids words that are hard to spell or easily confused with each other, and uses exactly 1,296 words (6 to the 4th power) so the security of each word can be precisely calculated.
How much entropy does a passphrase from this list actually have? Each word chosen from the 1,296-word list contributes about 10.3 bits of entropy (log base 2 of 1,296). A 6-word passphrase has roughly 62 bits of entropy — comparable to or stronger than a fairly long random password, while being made of real, memorable words.
Does adding a random symbol or number to a passphrase help much? It adds a little entropy, but usually far less than adding one more word does. A single extra Diceware word from a 1,296-word list adds about 10.3 bits, while a single unpredictable extra character typically adds somewhere in the range of 4 to 6 bits — so if you want meaningfully more strength, another word is a bigger lever than a bolted-on symbol.