🔤 Passphrase Generator
Builds passphrases from a fixed word list of common words, picked
with crypto.getRandomValues() — the same idea as Diceware. A handful of unrelated
words is typically easier to remember and type than a short "complex" password, for equal or
greater entropy.
Where the bits come from
The list is de-duplicated to 188 distinct words before anything is counted, and each word is drawn independently with rejection sampling. Strength is therefore the word count multiplied by the bits in one draw:
bits per word = log2(188) = 7.55
4 words = 30 bits 7 words = 53 bits
10 words = 76 bits + number = +6.5 bits
A passphrase is strong because a machine chose the words, not because the words are obscure. Assume an attacker has this list and knows the pattern; all that is left to guess is which words came up.
What the options do, and do not, add
- Capitalize each word and the separator add nothing measurable - both are fixed, published choices a cracker tries for free. Keep them for services that demand a capital, or for readability.
- Words per phrase is the only real control. Four words is 30 bits, which an offline attacker clears in seconds. The 2-digit number buys 6.5 bits, less than one extra word.
Frequently asked questions
How many words should a passphrase have?
With this 188-word list, eight gives 60 bits and ten gives 76. With a full 7,776-word Diceware list, six words reach 77 bits. Aim for 70 or more for a master password or anything that guards your email.
Does capitalising the words make a passphrase stronger?
Barely. Capitalising every word is a predictable pattern worth nothing; genuinely random capitalisation across four words adds four bits, while one more word adds seven and a half.
Is a passphrase safer than a random password?
Not per character - per unit of memory. Sixty bits takes ten characters of random ASCII you will never memorise, or eight ordinary words you can recall and read aloud over the phone.