Passphrase Generator
Random words, picked fairly from the EFF’s long word list in your browser: easy to type and remember, slow to guess. Change the number of words or the separator and a new one appears at once.
Strong. Would take about 45 years to guess at 10 billion guesses a second.≈ 65 bits
Words
Separator
More optionsseveral at once · history
Several at once
Generated in your browser with crypto.getRandomValues; nothing is sent anywhere, and the password is never put in the page address. Words from the EFF’s long word list (CC BY 3.0 US).
How this works: Method, 4 sources, Checked against 3 worked examples,
How this works
Method
Each character or word is picked with the browser’s crypto.getRandomValues (rejection sampling, so every choice is equally likely), with at least one character from every ticked set. Strength is length × log2(set size) bits (a passphrase: words × log2 of the list size); time to guess assumes half of all tries at 10 billion a second. “From a master password” takes each character from a byte of one SHA-256 hash of the master password and the site’s domain: same inputs, same password, with no salt or key stretching.
Sources
- Bonneau, J., "EFF’s New Wordlists for Random Passphrases" (Electronic Frontier Foundation, 2016)
- NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (NIST)
- EFF Large Wordlist for passphrases (CC BY 3.0 US; the four hyphenated words left out) (Electronic Frontier Foundation, 2016)
- FIPS 180-4, Secure Hash Standard (SHA-256) (NIST, 2015)
How it’s tested
3 worked examples for this page are checked by automated tests before every release: given the inputs, the tool must show the expected answer.
Changes
- From a master password now shows the exact domain used, offers the main site for a subdomain, and names any changed settings; the passwords are unchanged.
- Passphrases have a page of their own, with the word list explained and a table of strength by word count.
- Times to guess use the exact strength, and two billion years is no longer called longer than the age of the universe (13.8 billion).
- Passphrases now use the EFF long word list (7,772 words, 12.9 bits each, up from 1,287 words and 10.3 bits), with 4 to 8 words; the default five words are about 65 bits.
- Passwords from a master password moved out of the ⋯ menu into their own tab. They are byte-for-byte the same as before, and the master password and website are never saved or put in the page address.
- Added passphrases and a time-to-guess estimate; the history is now off unless you turn it on, and the page link carries your settings, never the password.
- Passwords now use the browser’s cryptographically secure random numbers instead of Math.random, with no bias toward any character.
- First published.
Worked example: how strong five words are
Each word is one of 7,772, chosen with equal chance, so each adds log₂ 7,772 = 12.92 bits of entropy. Five words give 5 × 12.92 = 64.6 bits, which is 2.8 × 10¹⁹ different passphrases.
An attacker who has stolen a fast password hash and tries 10 billion guesses a second needs, on average, half of them: 1.4 × 10⁹ seconds, about 45 years. Each extra word multiplies that by 7,772.
“Add a number” puts one of 90 two-digit numbers on one of the words, which adds log₂ 90 + log₂ 5 = 8.8 bits to five words: useful when a site insists on a digit, but a sixth word adds more.
How many words?
| Words | Entropy | Possible passphrases | Same as a random password of | Time to guess |
|---|---|---|---|---|
| 4 | 51.7 bits | 3.6 × 10¹⁵ | 8 characters | about 2 days |
| 5 | 64.6 bits | 2.8 × 10¹⁹ | 10 characters | about 45 years |
| 6 | 77.5 bits | 2.2 × 10²³ | 12 characters | centuries |
| 7 | 90.5 bits | 1.7 × 10²⁷ | 14 characters | billions of years |
| 8 | 103.4 bits | 1.3 × 10³¹ | 16 characters | longer than the age of the universe |
Why random words beat clever passwords
A password like Tr0ub4dor&3 looks strong but follows a pattern people use all the time: a word with letters swapped for look-alike digits and a symbol on the end. Cracking tools try those patterns first, so its real strength is far below what its length suggests, and it is hard to remember which letters were swapped.
A passphrase turns that around. The strength doesn’t come from looking random; it comes from the generator picking each word at random from a large list, so an attacker who knows exactly how it was made, list included, still has to try every combination. That is why the words must be picked for you: phrases people choose themselves, like song lyrics or a favourite saying, are guessed from huge lists of real phrases.
The EFF’s long word list
The words come from the Electronic Frontier Foundation’s long list, published in 2016 as a cleaner replacement for the original Diceware list, which had rare words, odd names and bits of punctuation in it. The EFF built theirs from data on which words people recognise most readily, then took out words that are hard to spell, homophones, and words that are vulgar or emotionally charged.
It has 7,776 words because that is 6⁵, the number of ways five six-sided dice can land, so you can also make a passphrase with real dice and the printed list. Words run from 3 to 9 letters, 7 on average. This generator leaves out the four hyphenated words (drop-down, felt-tip, t-shirt and yo-yo), so a hyphen always means a new word, leaving 7,772; strength is worked out from that smaller number.
Using a passphrase well
Use one for the few passwords you have to type or remember: a password manager’s master password, your computer login, the encryption of a phone or a backup. Seven or eight words are worth it there; five or six are plenty for most accounts. Let the password manager make random passwords for everything else.
If a site refuses spaces or insists on a capital and a number, keep Capitalise words on, pick the hyphen or full stop as separator and turn on Add a number. Write a new passphrase down somewhere safe until you know it by heart, and never reuse one between accounts.
Good to know
- The EFF’s long list has 7,776 words (6⁵, five dice), worth 12.9 bits each, with an average length of 7.0 characters; the EFF suggests six words, for 77 bits. Source: Bonneau, J., "EFF’s New Wordlists for Random Passphrases"
- NIST’s authentication guidelines ask services to allow passwords of at least 64 characters, to support passphrases, and not to impose composition rules such as a required mix of character types. Source: NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management
Need a random password of letters, digits and symbols instead, or one made from a master password? Open the password generator.
Frequently Asked Questions
How many words should a passphrase have?
Five words from this list give about 65 bits, enough for an ordinary online account, where the site also limits how fast anyone can guess. For anything that can be attacked offline, such as a password manager’s master password or an encrypted disk, use six to eight words: the EFF recommends six (about 78 bits).
Is a passphrase safer than a random password?
Not by nature: strength is just the number of possibilities. Five random words (64.6 bits) match a random password of about 10 characters drawn from every printable character. The passphrase wins because it is far easier to type correctly and to remember, so people actually use a strong one.
Can I add or change words myself?
You can, but each change you make by hand is a guessable human choice and adds less than it seems. If you don’t like a word, press the new-passphrase button for a fresh set rather than swapping one word for a favourite. Capitalising, the separator and the number are fine: they don’t weaken the random words.
Is the passphrase sent anywhere or saved?
No. The words are picked in your browser with crypto.getRandomValues, using rejection sampling so every word is equally likely, and the word list ships with the page. The address bar holds only your settings (number of words, separator), never the passphrase, and nothing is saved unless you turn on the copy history.