واژهها با crypto.getRandomValues و نمونهگیری پسزنی (rejection sampling) انتخاب میشوند، پس هر انتخاب روی فهرست واژههای بلند 7,776 واژهای EFF یکنواخت است — بدون سوگیری modulo، بدون نشانه آماری. بهصورت محلی تولید میشود؛ هیچ چیزی به هیچجا ارسال نمیشود. فهرست واژهها: EFF Diceware (CC BY 3.0 US).
(مستندات به انگلیسی)
What it does
Generates memorable, high-
entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
passphrases using the EFF diceware long wordlist — 7,776 common English words (6⁵, one entry per roll of five six-sided dice). Each word is chosen with your browser’s cryptographic random generator (crypto.getRandomValues) plus rejection sampling, so every word index is exactly uniform over the list. A plain random % 7776 would favor the first ~2,048 words; rejecting draws ≥ 62,208 before taking the modulo removes that bias entirely.
For every passphrase it shows the live entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.words × log₂(7776), so 12.9 bits per word — and the average crack time at 1 trillion guesses per second (a serious offline attack), computed as 2^(bits−1) / rate, the expected time to exhaust half the keyspace. Six words ≈ 77.5 bits ≈ 3.5 millennia against that attacker. Everything is generated locally in your browser; nothing is sent anywhere.
Why a passphrase beats a “clever” password: P@55w0rd! is a few mutations of a dictionary word — attackers try those transforms first, so it survives milliseconds. A random six-word passphrase like correct horse battery staple (the XKCD 936 idea) carries as much unpredictability as a 13-character random string, and a story you can actually remember makes it far easier to type correctly.
How to use it
- Set the word count (3–10). Each word adds ~12.9 bits; 6 is the sweet spot for most accounts, 7+ for anything critical.
- Pick a separator — space, dash, dot, underscore, or none. Any of them is fine; choose what your keyboard (and the site’s password rules) likes.
- Toggle Capitalize to title-case each word and + Digit to append one random digit — both help satisfy “must contain…” policies without meaningfully changing strength.
- Read the passphrase, Copy it, or hit Regenerate (Shuffle) for a fresh draw.
The URL stays shareable: your options are encoded as query parameters (?words=8&sep=dash&cap=1), so a bookmark restores your exact setup. The passphrase itself is never put in the URL.
Examples
| Settings | Output shape | EntropyEntropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity. |
Crack time @ 10¹² g/s |
|---|---|---|---|
| 6 words, space | rebuffer marrow paprika rivalry backfield unmask |
77.5 bits | ~3.5 millennia |
| 4 words, dash, capitalized | Puzzle-Overfeed-Correctly-Grotto |
51.7 bits | ~30 minutes |
| 8 words, dot, + digit | lurch.zealot.stomp.vixen.prow.tufted.madam.chili7 |
103.4 bits | ~2.1 billion centuries |
| 10 words, underscore | mutate_versa_biceps_unlit_spraying_proviso… |
129.2 bits | ~128,000 trillion centuries |
Rule of thumb: the displayed
entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
counts the words only (N × log₂ 7776). The optional digit adds ~3.3 more bits on top — a rounding error at these scales.
Good to know
- The wordlist is the security. Diceware strength comes from uniform random selection, not from obscure words. Never pick the words yourself — humans are terrible at randomness, and attackers model human choices.
- 7,776 words, no repeats needed. Repeats are allowed and fine: each draw is independent, so
entropyentropyThe unpredictability of a secret, measured in bits. Each added bit doubles the guesses an attacker needs; strength comes from length and randomness, not from obscurity.
is exactlyN × 12.925bits either way. - Attack model. The 10¹² guesses/sec rate assumes the attacker already stole the hashed database and is running a fast offline attack. Online attacks are rate-limited and vastly slower.
- Don’t reuse. One passphrase per site. Pair it with a password manager so memorability is a bonus, not a requirement.
- Credits. Wordlist: EFF Diceware large list (2016), licensed CC BY 3.0 US. The passphrase concept was popularized by XKCD 936.
- A Go CLI twin and per-language source snippets for this tool are on the roadmap — the pure logic in
src/lib/passphrase-generator.tsis the contract they follow.