Back to the tool

Diceware Passphrase vs Random Password

Is a diceware passphrase safer than a random password? At equal entropy, no: bits are bits, and the math does not care what your secret looks like. But you are not a math problem. You are a person who has to type the thing, remember the thing, and not reuse the thing. That is where the real difference lives.

The question comes up every time someone watches me type a password. They see a string like k9#Xv!2mQz$p on one screen and correct horse battery staple on another, and they want to know which one is safer. The honest answer is boring: the entropy count decides, and the shape is packaging. A secret's strength is measured in bits. Everything else is how it feels in your hands.

The math, worked out with real numbers

Diceware draws each word from a list of 7,776 entries. That is log2(7776), which works out to 12.925 bits per word. Five words give 64.6 bits. Six give 77.55 bits. Seven give a little over 90. These numbers are exact, but only if the words are picked uniformly at random, which is the entire point of the dice.

A random password drawn from the 94 printable ASCII characters gives 6.55 bits per character. A 9 character password is 59 bits. A 12 character password is 78.6 bits, almost exactly a 6 word diceware passphrase. A 16 character password is 104.9 bits, stronger than 6 words and a touch stronger than 8.

So here is the famous comparison, done properly: 5 diceware words at 64.6 bits versus 9 random characters at 59 bits. The words win, by a factor of about 50 in guessing difficulty, and they are far easier to type. Security researchers worked this out years ago on Stack Exchange, and the analysis hinges on one word: equiprobable. Every option has to be equally likely, chosen by dice or a cryptographic random number generator. That single assumption does all the work in the math.

The part the math misses: your hands and your brain

Almost nobody guesses your password by brute force anymore. They phish it, buy it from a breach, or replay it from a password dump. So the realistic question is not which secret survives a supercomputer. It is which secret you will actually use correctly.

If your secrets live in a password manager, the shape barely matters, because you never type them. Random strings are perfect there. Let the generator make a 20 character monster and move on.

The shape matters for the passwords you type: your manager's master password, your laptop login, the code on your phone. I have watched people type a 16 character random password on a phone keyboard and it is miserable. Four trips to the symbols page, two typos, a lockout timer. A 6 word passphrase is one spacebar and six short words. Eight seconds, right the first time.

Memorability is a security property. A passphrase you can actually recall is one you will not weaken, one you will not reuse across sites, one you will not write on a sticky note. The xkcd comic that started all of this got the principle exactly right and the word count slightly dated: four words is 51.7 bits, which I would not recommend as a master password today. Six words is where I land. And I know the six word recommendation sounds oddly specific. It is just the point where the math clears my comfort zone and the typing stays painless.

The one rule both methods share

Here is the part people skip. Neither method works if you pick the words yourself. Humans are catastrophic at randomness. The entropy numbers above only hold when every option is equally likely, chosen by dice or a crypto RNG. The moment you "improve" a diceware result by swapping a word you do not like, you have cut the entropy by an amount you cannot calculate.

Same for random passwords. If you "fix" the generated string into something memorable, you have done the same damage. The rule is simple and absolute: never touch the output. Roll it, accept it, store it. The generator on this site uses your browser's crypto randomness, the same engine behind TLS keys. Let it do its job.

So: diceware for the handful of secrets you type, random strings for the hundreds you store. If you take one thing from this page, make it the six words. That is my default for a master password, and I have not found a reason to change it.

Frequently asked questions

How many bits of entropy does each diceware word add?

12.925 bits. The standard list has 7,776 words, and log2(7776) is 12.925. Six words give 77.55 bits, which is the level I recommend for a master password.

Is a 4 word passphrase enough?

Four words give 51.7 bits. That is fine for a low value login you type often, but it is below what I would trust for a password manager master secret. Six words is my default.

Can I choose my own words to make the passphrase memorable?

No. Human picked words are predictable, and the entropy math only holds for uniformly random selection. Roll dice or use a cryptographic random number generator, and accept whatever comes out.

Does capitalizing words or adding a symbol make it stronger?

A little, if the changes are random. Predictable changes, capitalizing the first word or tacking ! on the end, add almost nothing, because attackers guess those patterns first.

Should I use diceware or my password manager's random generator?

Both. Use diceware for the secrets you type from memory: the manager's master password, your device login. Use the manager's random generator for everything it stores and fills for you.

Related reading: How Many Words Does Your Passphrase Need? Entropy Math, Worked Out · The One Passphrase Setup: Why Your Password Manager Deserves a Great Master Secret · Can You Put Spaces in a Password? Yes, and Most Sites Should Accept Them

Try the tool

Everything above is easier to believe once you have seen it in action. Generate a passphrase now on the homepage. It runs entirely in your browser and takes about three seconds.

Keep reading

How Many Words Does Your Passphrase Need? Entropy Math, Worked Out

Get new free tools by email

Want the next guide in your inbox? I publish one practical guide per new tool. Subscribe to the free newsletter on Substack. No spam, unsubscribe anytime.