Diceware & Human-friendly secret · 02

Secure random passphrase generator for memorable secrets you can type.

Create a strong passphrase from independently selected dictionary words for master credentials, disk encryption, and device logins. Every word is chosen locally with Web Crypto randomness.

Generated locallyCryptographic randomNo history
Passphrase generator● Web Crypto ready
AnalyzingEstimated resistance
6

The entropy estimate is based on independent selections from this generator's word list.

Local

No generation request

Every selection happens inside this browser tab. The server only delivered the page.

Temporary

No saved history

Results are never written to cookies, local storage, session storage, or a database.

Unbiased

Fair random selection

Rejection sampling removes modulo bias before values are mapped to characters or words.

A random passphrase is ideal when humans must type or remember the secret.

A random password is great for a password manager vault. A random passphrase (Diceware style) is often better for a master password, encrypted drive, firmware login, or any credential you must occasionally type yourself.

Practical advice: Start with six words from the EFF Long Wordlist used here. Each added random word contributes about 12.9 bits of entropy. Fixed capitalization and separators add readability, not randomness.

Deciding whether this format fits the job? Compare a passphrase with a random password before you save the result.

Word source: EFF Long Wordlist (7,776 distinct words), by EFF / Joseph Bonneau, used under CC BY 3.0 US. The local copy removes dice indexes. Review the implementation in our public source repository.

Random words, not a favorite sentence or lyric

A sentence, lyric, address, pet name, or familiar proverb may look long but is not random. Modern dictionary attacks test common phrases and leaked database corpuses. This tool selects each word independently from an unbiased word list.

Separators and capitals enhance readability

Treat hyphens, periods, or spaces as formatting for compatibility and ease of reading, not the main source of mathematical strength. Word count is the primary security dial. Add another random word when you need higher cryptographic margin.

Where passphrases do and do not belong

Do not replace unique password-manager-generated passwords with one memorable passphrase reused everywhere. A passphrase should still be dedicated and unique to its specific purpose.

Before you use the result.

How many words should a secure passphrase have?

This generator uses the 7,776-word EFF Long Wordlist. Six independent selections provide about 77.5 bits before an optional random number. Start with six words, and add more for additional margin or to meet your service's requirements.

Is a passphrase stronger than a random password?

It depends on the word list, word count and character pool. Six words from this list provide about 77.5 bits. Twenty uniformly random alphanumeric characters have a search space of about 119 bits before character-group constraints. A passphrase trades extra length for easier reading and typing.

Are generated passphrases sent to a server?

No. Word selection happens 100% client-side in your browser using window.crypto.getRandomValues(). Nothing is transmitted or saved.