Runs in your browser
Passphrase Generator
Words you can remember, and a password manager for the rest
Reusing passwords, and writing them on a loose sheet of paper, are certainly not safe ways to keep the passwords for your apps and online accounts. This tool is meant to give you the proper answer instead: use it together with a password manager and you will be meaningfully safer.
Six is the usual choice. Five is still plenty. Four is not, which is why the slider starts at five.
This does not make the phrase harder to guess. Pick whichever is easiest for you to read and type.
About 77.5 bits of entropy
drawn from 7776 words at 12.925 bits per word, characters long
Bits count guesses, and each extra bit doubles them. The table further down turns that number into something you can picture: years.
Two things that work together
Count the passwords you type from memory. Two or three, probably: the laptop, the phone, maybe one account you sign into everywhere. Now count the accounts you have. A password manager is an app that keeps all of them in one locked file. One of the companies that sells them puts the average at 168, which is a self-interested number for them to publish, but nobody seriously argues it is under a hundred. Whatever your real number is, you are not inventing that many passwords. Nobody is. They come from somewhere, and for most people that somewhere is a handful of passwords used over and over. Source: NordPass, 2024
Be honest with me: you reuse the same password on most of your online accounts, don't you? If I am right, you probably have no idea how much risk that carries.
A password you invented is a password somebody else can guess. Not by hand. There are programs that try millions of candidates one after another, and they do not begin at aaaa and work through every variation in order. They begin with lists of the passwords people actually choose, which open at 123456. Then they work through word lists: every word in the language, plus names, teams, bands and films. Each one gets tried with the obvious disguises too. A capital in front. A digit and a symbol on the end. An o written as a zero. P@ssw0rd!23 is not a clever password; it is the first page of the playbook.
Source: the most common passwords, NordPass
Reusing one is worse, and it is the danger people wave off. It takes no guessing at all. When a company is breached, the email-and-password pairs it loses are tried automatically against hundreds of other sites, and every account that shared that password opens. That costs the attacker almost nothing, and it is the same work whether ten accounts match or ten thousand do. How strong the password was does not come into it. Twenty characters you used twice is twenty characters somebody else already has. And nobody is attacking you personally: you are a line in a list of millions, and the list gets replayed for years after the breach that produced it.
Where you keep them matters as much, and none of the usual places is locked: a notes app, a spreadsheet, a text file on the desktop, an email to yourself. Anything that can read your files can read your passwords, and the malware that steals passwords goes looking for exactly those files. In Verizon's 2025 breach data, more than half of ransomware victims had their passwords sitting in stolen logs before the attack even started. Source: Verizon DBIR 2025
So there are two things to fix, and this page does the smaller one. It makes the two or three passwords you keep in your head, and they come out as random words, like ridge-dolphin-sober-mango-piano. Nobody chose them, including you. That is the whole trick.
For all the others, use a password manager. It invents a different password for every site and remembers all of them, so you never have to. Bitwarden is free and open source, KeePassXC keeps everything on your own disk if you would rather avoid the cloud, and 1Password and Proton Pass are fine too.
You can use this page for those too. Generate a passphrase here, paste it into the manager as that site's password, and let the manager remember it from then on. It is worth doing for the accounts you sometimes type by hand: a TV, a games console, a phone with no autofill. Forty random characters on a TV remote is a punishment; six words is not. For everything else, the manager's own generator is fine, since you will never see those passwords anyway.
Does that not put everything behind one password? It does. One password you actually remember beats a hundred you recycle. The file the manager keeps is locked with it, so a thief who steals the file still has to guess it. All the weight lands on that one password, which is what the rest of this page is about.
What this looks like when it goes wrong
None of those three is theoretical. Four that are worth knowing about:
-
RockYou, 2009
A company called RockYou kept 32 million passwords in plain text and lost every one of them in a single break-in. The list of what people had actually chosen became
rockyou.txt, which ships with Kali Linux and is still the first thing a cracking tool reaches for. Passwords picked in 2009 are the opening guesses aimed at you today. - 23andMe, 2023 Nobody broke into 23andMe. Attackers signed in as roughly 14,000 people, one account at a time, using passwords those people had already used on sites that were breached earlier. Once inside, a profile-sharing feature reached data belonging to about 6.9 million people. The company later agreed to pay $30 million to settle. No exploit and no clever code: fourteen thousand front doors, opened with keys that were already lying around.
- Dropbox, 2012 One employee used his LinkedIn password at work too, LinkedIn was breached, and 68 million Dropbox account records left the building behind that single password.
- Snowflake, 2024 Nothing was guessed here either. Attackers used passwords that malware had quietly collected from people's own computers, some of it running since 2020, and signed into about 165 companies' cloud accounts. Ticketmaster alone lost 560 million customer records.
Two of those four were reuse and nothing else. The other two never involved guessing anybody's password. RockYou handed the guesses to everyone who came after it, and the Snowflake attackers read the answers off people's own laptops.
In the same Verizon report, stolen passwords come first on the list of ways in, for the second year running.
The manager is what ends reuse. Every site gets a different password and you never have to recall any of them, which takes the two reuse cases above off the table. What it cannot do is protect the password that opens the manager, because that one cannot be stored inside it. The key does not fit in the box it locks, and your computer login and your phone sit in the same position. That leaves two or three passwords that have to be memorable and hard to guess at once. People usually settle that with a pet's name and a year. Random words settle it the other way, and that is the only reason this page sits beside the advice to install a manager rather than instead of it.
What to do today:
- Install a password manager.
- Make its master password here, with six words. Write it on paper until you know it by heart, then destroy the paper.
- Let the manager replace your reused passwords a few sites at a time. Start with your email, then anything with money in it.
The technical version: why reuse is the expensive mistake
The attack that walks one leaked password into your other accounts has a name: credential stuffing. A password manager is the only control that ends it, because every password it makes is different by construction. Everything except the two or three you type from memory belongs in there. Most of those can be a long random string you will never look at; the exception is an account you still have to type by hand, where a passphrase is kinder and no weaker than the site allows.
Current guidance is not merely advice on this point. NIST SP 800-63B-4 §3.1.1.2 says verifiers SHALL allow the use of password managers, and SHOULD permit pasting into the password field. A site that blocks either one is out of compliance, not being careful.
Words, or random characters?
Your password manager can invent xK7#pLm2$vQ9 as easily as this page invents six words, and for every password it types for you, that is the better answer. It is shorter, and you never have to look at it.
The few you type yourself are a different problem. Six words from this page is worth the same as 12 of those characters, drawn the same way, by the same kind of random number generator. Neither is guessable. Only one of them can be held in your head, read out to somebody over the phone, or typed on a TV remote without three attempts. It costs you more keystrokes and saves you the lookup.
And there is one password no manager can make for you, whichever generator you like: the one that opens the manager. It has to exist before the vault does, and it cannot be kept inside the thing it unlocks. Your computer login and your phone are in the same position.
Some managers offer a passphrase mode of their own, and it is a good one. Use it if you have it. This page shows you the arithmetic rather than a setting, and it works before you have installed anything at all.
The technical version: the arithmetic behind that comparison
A random string over the 95 printable ASCII characters carries log2(95) bits each, so 77.5 bits is 12 characters. Per keystroke the characters win outright, since a six-word phrase is two to three times as long to type. Per unit of human memory they lose badly, and memory is the only currency that matters for a secret nobody can look up for you.
That assumes the manager's generator has every character class switched on. Turn symbols off and the alphabet shrinks to 62, which costs another character or two to carry the same entropy. The direction of the argument does not move. What would move it is a site with a length cap: at sixteen characters a passphrase is out of room, and a random string is the only thing that fits.
How many words should I pick?
Six, unless you have a reason to choose otherwise. That is where this page starts, and it is what the people who invented this method recommend for anything you would call important.
Five is still plenty, so take it if six feels like too much to hold in your head. Four is where it stops being safe, which is why the slider will not go there.
That floor moved while I was building this. I had it at six words and dropped it to five only after working out the table below. Five words survives every row there that stores a password properly, by thousands of years. Four does not last a quarter of an hour against the top row. That is the whole reason for the line.
The technical version: the bits behind those two numbers
In practice: at 77.5 bits nobody is guessing your phrase, and at four words somebody might. How far apart those two cases sit depends almost entirely on how the site you logged into stored your password, which is what the table below is for. It is also the reason the slider will not go under five.
The ceiling I am less sure about. Ten words is far past anything an attacker can reach, so the argument for it is only that some people want headroom, and the argument against is that nobody will retype it. I left it at ten and could be talked out of that.
How long an attack actually takes
Read a row like this. A company you have an account with is breached. The attacker takes the file with everyone's passwords in it, then guesses at yours around the clock on rented machines. How long that takes depends on how carefully the company stored that file, and the gap between careful and careless is enormous.
{# No localize-off here: the row labels and cells are formatted in Python with the active locale, so a dot in the bits column beside "3,8 milhões de anos" in the cells put two conventions in one table. #}| How the site stored your password | 4 words 51.7 bits | 5 words 64.6 bits | 6 words 77.5 bits |
|---|---|---|---|
| Stored carelesslyNTLM, unsalted — what NIST forbids | 13 minutes | 71 days | 1,500 years |
| Stored weakly, as some real accounts werePBKDF2-SHA256, 500 iterations — LastPass's weakest 2022 vaults | 149 days | 3,200 years | 25 million years |
| Stored properly, as a password manager doesPBKDF2-SHA256, 600,000 iterations — Bitwarden's default | 490 years | 3.8 million years | 30 billion years |
| Stored properly, as this site doesPBKDF2-SHA256, 1,000,000 iterations — Django's default | 820 years | 6.4 million years | 49 billion years |
| Stored with a deliberately slow recipebcrypt, cost 12 — Django's bcrypt hasher | 5,000 years | 39 million years | 300 billion years |
The first row is a company that stored passwords badly. Every row under it did something to slow a thief down, and the further down you read the more it did. Against all of them, five words holds for thousands of years or longer. Four words holds the careless row for thirteen minutes. That is the entire argument for the floor being five.
The technical version: the attacker, the rates, and the sources
One attacker, spelled out: 8 RTX 4090s, which is a rig you can rent by the hour rather than a government, guessing offline against a stolen password database. The attacker has both wordlists, knows how many words you asked for and knows which separator you picked. Every figure is an average — half the keyspace, since a guessing attack finds the average secret halfway through. The rates are hashcat's published benchmark numbers for that card, and the two Django rows read this deployment's own hasher settings rather than a number I typed in.
The top row is the only one four words loses outright, and it is also the only row describing storage that is against the rules: NIST has required since 2017 that stored passwords be salted and hashed with a real password hashing scheme, at as high a cost factor as the verifier can stand. So that row is not a site behind on its patches, it is a site out of compliance. The bottom rows run past the age of the universe; they are in the table to show where the numbers stop meaning anything, not because I expect anyone to leave the rig running that long.
The second row is the one the floor is built on, and it is not hypothetical. When LastPass lost its encrypted vault backups in 2022, some accounts were still deriving their key with 500 PBKDF2 iterations, because raising the default in 2018 never migrated the accounts that already existed. That is the weakest real password storage I can point at inside a security product, and five words still holds it off for thousands of years. Master passwords were cracked out of that data and vaults were emptied — none of them were five random words.
Between those two rows sits what most sites actually do. A survey of open-source web platforms found just under half of the application frameworks defaulting to bcrypt, with most of the rest on PBKDF2 or a salted SHA-2 variant; the content management systems did worse. Unsalted fast hashing is the outlier in that data, not the coin flip I assumed before I went looking.
So five words is the floor and six is the default, and the gap between them is not fussiness. Every salted row gives five words thousands of years or more. Six is what Diceware's author has recommended as a minimum for file encryption since the 1990s, and what EFF repeated when it published the list this page uses, and it is the number I would pick for a password manager's master password: it costs you one more word and multiplies every figure in that row by 7776. Four is on the table so you can see the figure the slider is keeping you away from, rather than taking my word that it is too few.
Where these numbers come from:
- NIST SP 800-63B-4, §3.1.1.2 — passwords SHALL be salted and hashed; composition rules SHALL NOT be imposed; password managers SHALL be allowed and pasting SHOULD be permitted.
- Hashcat v6.2.6 benchmark, RTX 4090 — every guess rate in the table: NTLM (mode 1000), PBKDF2-HMAC-SHA256 (10900) and bcrypt (3200), scaled from one card.
- Ntantogian, Malliaros & Xenakis, Evaluation of password hashing schemes in open source web platforms, Computers & Security 84 (2019) — bcrypt is the default in 48.94 percent of the frameworks surveyed.
- LastPass, Security Incident December 2022 Update — what was taken, and what protected it.
- Palant, LastPass breach: The significance of these password iterations — the accounts left on 500 iterations, and what that cost them.
- Reinhold, The Diceware Passphrase Home Page — the method itself, and the six-word minimum for file encryption.
- EFF, New Wordlists for Random Passphrases — the English list this page ships, and why its words are what they are.
- Bitwarden, Encryption key derivation — 600,000 PBKDF2 iterations by default, following OWASP.
What “bits of entropy” means
Think of dice. One die has six faces, two dice have 36 combinations, three have 216. Bits are that same idea in a different unit: every bit doubles the number of possibilities. Ten bits is about a thousand, twenty bits is about a million, and thirty is about a billion.
Each word you add multiplies that pool by the whole length of the list. That is what the second line of the readout is for: 12.925 bits per English word. One more word buys more than any amount of punctuation.
The technical version: what the number describes, and what it does not
Every bit doubles something. Two possibilities at one bit, 1,024 at ten, roughly a million at twenty. The 77.5 above is that same scale: the size of the pool this phrase came out of, written as a power of two.
Here is the part I took longest to hold onto. The number describes how the phrase was chosen, not the phrase. Run whatever measurement you like on correct-horse-battery-staple; none of them return a number of bits. The figure exists because the draw was uniform over a list of known size, and for no other reason. Ask a person for six random words and it collapses. They reach for concrete nouns, avoid repeats, and pick from the few thousand words they happen to like.
Nothing is saved, and you can verify that
The phrase is made inside your browser and never sent to me. It is not in my server logs, not in my analytics, and not in anything sitting between you and this page, because it never travelled.
Open your developer tools, watch the network tab, and press the button. Nothing goes out, and that takes ten seconds to check rather than my word. What does load, before you press anything, is what every page here loads: the wordlist files, a stylesheet and icons from a CDN, and the analytics that counts the visit. None of them is ever sent a phrase, because the phrase is made after all of that and stays in the tab.
Your settings — word count, separator, language — are kept in this browser's local storage so the page remembers them. The passphrase itself is never written there.
The technical version: where the randomness comes from
Every passphrase here is produced in your browser by crypto.getRandomValues(). It is never sent anywhere, so it never reaches my access logs, my analytics, or the logs of whatever sits in front of this site. A value that crosses the network cannot honestly be called unsaved, which is why there is no server-side version of this feature.
There is a limit to that, and it is worth stating rather than leaving you to find it. "Stays in the tab" holds as long as the page you received is the page I published. Everything running in this document shares an origin with the box the phrase appears in and could read it: my own script, the stylesheet, the analytics tag. The two CDN files are pinned with subresource integrity, so a modified copy is refused by your browser instead of executed. The analytics tag cannot be pinned that way, and this site still has no Content-Security-Policy, which is the next thing I would fix. If you would rather not extend that trust at all, the four lines of Python this page falls back to without JavaScript do the same job offline, and both wordlists are downloadable from /static/blog/wordlists/.
The wordlists are public on purpose
Anyone can download both lists, and that takes nothing away. The strength is in the dice, not in keeping the list secret. There are 7776 words per language, and every one has exactly the same chance of being picked. If hiding the list were what kept you safe, the safety would be imaginary.
The technical version: what the entropy figure assumes, and where the lists come from
Assume an attacker has both lists, knows their size, and knows how many words and which separator you chose. The entropy figure above is calculated under that assumption, which is what makes it a real number. Strength comes from the uniform draw. Hiding the list would only stop you checking the arithmetic.
The English list is the EFF long list, 7776 words, used unchanged. The Portuguese one is built to the same size from a frequency list crossed with a Portuguese dictionary, then filtered by length, by a blocklist, and against any word that is another entry plus one trailing letter. Matching sizes means matching entropy, so six words is worth 77.5 bits in either language.
Sources and licences: the English list is EFF long wordlist (eff_large_wordlist.txt), used under CC BY 3.0 US. The Portuguese list is built by scripts/build_wordlists.py from sources under MIT + LGPL-3.0; the script pins every source by SHA-256 and can rebuild both lists to prove the committed files match.
Why the Portuguese words have no accents
The Portuguese list is written without accents: coracao, not coração. When you save one, copy and paste it rather than retyping. And if it is a phrase you will type from memory, remember there are no accents in it. Type the accented spelling and it will not match what you saved, even though the two look identical on screen.
The technical version: two spellings that look identical
The Portuguese words carry no accents: coracao, not coração. coração can be encoded two ways that look identical on screen — one with a single ç, one with a c followed by a combining cedilla — and those are different byte sequences. Password hashers compare bytes, and Django does not normalise before hashing, so the same phrase saved one way and typed the other will not match. Stripping the accents leaves one spelling and one encoding per phrase. It also leaves a misspelling: type coracao from memory and you will reach for the accented form, and it will fail. Copy the phrase rather than retyping it.
What it deliberately will not do
There is no button to add a capital letter, a digit or a symbol. Those rules are the reason Password123! satisfies almost every password policy in the world and still appears hundreds of thousands of times in lists of breached passwords.
The technical version: what the guidance says about those rules
There is no button to capitalise a word, append a digit, or swap in a symbol. Those rules are why Password123! is both fully compliant with most password policies and has turned up hundreds of thousands of times in breach corpora. NIST's current guidance tells verifiers not to impose them, and I am not going to add them back here.
The reasoning in full, with the measurements behind it: Weak Passwords and Validators: Why Django's Four Defaults Accept a Password Seen 295,389 Times in Breaches