Wordlists
All word-based passphrases use the EFF diceware wordlists by the Electronic Frontier Foundation (2016): the long list (7,776 words) and short lists 1 and 2 (1,296 words each). They are published at eff.org/dice under the Creative Commons Attribution 3.0 United States licence. We use the words unchanged; a build script downloads them from eff.org and checks the count and dice codes of every row. Joseph Bonneau's EFF article "Deep Dive: EFF's New Wordlists for Random Passphrases" explains how they were chosen.
Method
- Diceware, the method of picking words with five dice, was published by Arnold G. Reinhold in 1995.
- Randomness comes from the Web Crypto API's
crypto.getRandomValues, with rejection sampling so each word is exactly equally likely. - Entropy is calculated as words × log2(list size), plus log2 of the options for every other random choice. Guess-time figures use stated, illustrative attacker speeds.
Guidance
- NIST Special Publication 800-63B (Revision 4), Digital Identity Guidelines: Authentication and Authenticator Management, National Institute of Standards and Technology.
- Randall Munroe, "Password Strength", xkcd comic #936 (2011).
- IEEE 802.11 / Wi-Fi Alliance: WPA2 and WPA3-Personal passphrases are 8–63 ASCII characters.
AI helper
The optional "fit my passphrase to these rules" helper sends only the rules text you paste to an AI model (OpenAI's GPT-6 Luna, via Vercel AI Gateway). It returns suggested generator settings. Passphrases are never sent.