🔤 Passphrase Generator

Builds passphrases from a fixed word list of common words, picked with crypto.getRandomValues() — the same idea as Diceware. A handful of unrelated words is typically easier to remember and type than a short "complex" password, for equal or greater entropy.

Where the bits come from

The list is de-duplicated to 188 distinct words before anything is counted, and each word is drawn independently with rejection sampling. Strength is therefore the word count multiplied by the bits in one draw:

bits per word = log2(188) = 7.55
4 words  = 30 bits    7 words  = 53 bits
10 words = 76 bits    + number = +6.5 bits

A passphrase is strong because a machine chose the words, not because the words are obscure. Assume an attacker has this list and knows the pattern; all that is left to guess is which words came up.

What the options do, and do not, add

188 words is a short list; a standard Diceware list holds 7,776, worth 12.9 bits a word, so six Diceware words beat ten from here. Use eight or more here for anything real. Nothing generated is transmitted or stored.

Frequently asked questions

How many words should a passphrase have?

With this 188-word list, eight gives 60 bits and ten gives 76. With a full 7,776-word Diceware list, six words reach 77 bits. Aim for 70 or more for a master password or anything that guards your email.

Does capitalising the words make a passphrase stronger?

Barely. Capitalising every word is a predictable pattern worth nothing; genuinely random capitalisation across four words adds four bits, while one more word adds seven and a half.

Is a passphrase safer than a random password?

Not per character - per unit of memory. Sixty bits takes ten characters of random ASCII you will never memorise, or eight ordinary words you can recall and read aloud over the phone.