Skip to content

Passphrase Generator

Random words, picked fairly from the EFF’s long word list in your browser: easy to type and remember, slow to guess. Change the number of words or the separator and a new one appears at once.

Strong. Would take about 45 years to guess at 10 billion guesses a second.≈ 65 bits

Words

Separator

More optionsseveral at once · history

Several at once

Generated in your browser with crypto.getRandomValues; nothing is sent anywhere, and the password is never put in the page address. Words from the EFF’s long word list (CC BY 3.0 US).

How this works: Method, 4 sources, Checked against 3 worked examples,

How this works

Method

Each character or word is picked with the browser’s crypto.getRandomValues (rejection sampling, so every choice is equally likely), with at least one character from every ticked set. Strength is length × log2(set size) bits (a passphrase: words × log2 of the list size); time to guess assumes half of all tries at 10 billion a second. “From a master password” takes each character from a byte of one SHA-256 hash of the master password and the site’s domain: same inputs, same password, with no salt or key stretching.

How it’s tested

3 worked examples for this page are checked by automated tests before every release: given the inputs, the tool must show the expected answer.

Changes

  • From a master password now shows the exact domain used, offers the main site for a subdomain, and names any changed settings; the passwords are unchanged.
  • Passphrases have a page of their own, with the word list explained and a table of strength by word count.
  • Times to guess use the exact strength, and two billion years is no longer called longer than the age of the universe (13.8 billion).
  • Passphrases now use the EFF long word list (7,772 words, 12.9 bits each, up from 1,287 words and 10.3 bits), with 4 to 8 words; the default five words are about 65 bits.
  • Passwords from a master password moved out of the ⋯ menu into their own tab. They are byte-for-byte the same as before, and the master password and website are never saved or put in the page address.
  • Added passphrases and a time-to-guess estimate; the history is now off unless you turn it on, and the page link carries your settings, never the password.
  • Passwords now use the browser’s cryptographically secure random numbers instead of Math.random, with no bias toward any character.
  • First published.

How we make toolsReport a mistake

Worked example: how strong five words are

Each word is one of 7,772, chosen with equal chance, so each adds log₂ 7,772 = 12.92 bits of entropy. Five words give 5 × 12.92 = 64.6 bits, which is 2.8 × 10¹⁹ different passphrases.

An attacker who has stolen a fast password hash and tries 10 billion guesses a second needs, on average, half of them: 1.4 × 10⁹ seconds, about 45 years. Each extra word multiplies that by 7,772.

“Add a number” puts one of 90 two-digit numbers on one of the words, which adds log₂ 90 + log₂ 5 = 8.8 bits to five words: useful when a site insists on a digit, but a sixth word adds more.

How many words?

Strength by word count, for words picked at random from 7,772, and the random password of every printable character (94 of them) with the same strength. Time to guess is the average at 10 billion guesses a second.
WordsEntropyPossible passphrasesSame as a random password ofTime to guess
451.7 bits3.6 × 10¹⁵8 charactersabout 2 days
564.6 bits2.8 × 10¹⁹10 charactersabout 45 years
677.5 bits2.2 × 10²³12 characterscenturies
790.5 bits1.7 × 10²⁷14 charactersbillions of years
8103.4 bits1.3 × 10³¹16 characterslonger than the age of the universe

Why random words beat clever passwords

A password like Tr0ub4dor&3 looks strong but follows a pattern people use all the time: a word with letters swapped for look-alike digits and a symbol on the end. Cracking tools try those patterns first, so its real strength is far below what its length suggests, and it is hard to remember which letters were swapped.

A passphrase turns that around. The strength doesn’t come from looking random; it comes from the generator picking each word at random from a large list, so an attacker who knows exactly how it was made, list included, still has to try every combination. That is why the words must be picked for you: phrases people choose themselves, like song lyrics or a favourite saying, are guessed from huge lists of real phrases.

The EFF’s long word list

The words come from the Electronic Frontier Foundation’s long list, published in 2016 as a cleaner replacement for the original Diceware list, which had rare words, odd names and bits of punctuation in it. The EFF built theirs from data on which words people recognise most readily, then took out words that are hard to spell, homophones, and words that are vulgar or emotionally charged.

It has 7,776 words because that is 6⁵, the number of ways five six-sided dice can land, so you can also make a passphrase with real dice and the printed list. Words run from 3 to 9 letters, 7 on average. This generator leaves out the four hyphenated words (drop-down, felt-tip, t-shirt and yo-yo), so a hyphen always means a new word, leaving 7,772; strength is worked out from that smaller number.

Using a passphrase well

Use one for the few passwords you have to type or remember: a password manager’s master password, your computer login, the encryption of a phone or a backup. Seven or eight words are worth it there; five or six are plenty for most accounts. Let the password manager make random passwords for everything else.

If a site refuses spaces or insists on a capital and a number, keep Capitalise words on, pick the hyphen or full stop as separator and turn on Add a number. Write a new passphrase down somewhere safe until you know it by heart, and never reuse one between accounts.

Good to know

Need a random password of letters, digits and symbols instead, or one made from a master password? Open the password generator.

Frequently Asked Questions

How many words should a passphrase have?

Five words from this list give about 65 bits, enough for an ordinary online account, where the site also limits how fast anyone can guess. For anything that can be attacked offline, such as a password manager’s master password or an encrypted disk, use six to eight words: the EFF recommends six (about 78 bits).

Is a passphrase safer than a random password?

Not by nature: strength is just the number of possibilities. Five random words (64.6 bits) match a random password of about 10 characters drawn from every printable character. The passphrase wins because it is far easier to type correctly and to remember, so people actually use a strong one.

Can I add or change words myself?

You can, but each change you make by hand is a guessable human choice and adds less than it seems. If you don’t like a word, press the new-passphrase button for a fresh set rather than swapping one word for a favourite. Capitalising, the separator and the number are fine: they don’t weaken the random words.

Is the passphrase sent anywhere or saved?

No. The words are picked in your browser with crypto.getRandomValues, using rejection sampling so every word is equally likely, and the word list ships with the page. The address bar holds only your settings (number of words, separator), never the passphrase, and nothing is saved unless you turn on the copy history.