Diceware
Method using dice to generate secure passphrases from word lists.
Diceware is a method for creating passphrases, passwords, and other cryptographic variables using ordinary dice as a hardware random number generator. It was created by Arnold Reinhold in 1995. The method involves rolling a six-sided die five times per word, assembling the results into a five-digit number, and using that number to look up a word in a cryptographic word list. The original Diceware list contains 7,776 unique words, and lists have been compiled for over two dozen languages.
- creator
- Arnold Reinhold
- year_created
- 1995
- field
- Cryptography, password security
- known_for
- Diceware passphrase generation method
- entropy_per_word
- 12.9 bits
- original_minimum_words
- 5 words (64.6 bits)
- updated_minimum_words_2014
- 6 words (77.5 bits)
Lore & Background
Diceware was introduced in 1995 by Arnold Reinhold as a practical way for average users to create strong, memorable passphrases. The method relies on physical dice rolls to produce random five-digit numbers, each mapping to a word in a publicly available list of 7,776 words. The security of a Diceware passphrase depends solely on the number of words selected and the size of the word list, not on keeping the list secret. In 2014, Reinhold updated his recommendation from a minimum of five words to at least six words, reflecting increased computing power available to attackers.
Reader's Guide
Diceware's significance lies in its ability to generate high-entropy passphrases using a simple, verifiable physical random process, avoiding the risks of software-based random number generators. Each word contributes 12.9 bits of entropy, assuming the attacker knows the method, word list, and passphrase length. The Electronic Frontier Foundation published alternative word lists in 2016 emphasizing ease of memorization, though these may require typing more characters. The method's legacy includes influencing password strength discussions, as seen in the XKCD #936 comic, which depicts a similar approach. Diceware remains a recommended technique for creating strong passphrases resistant to brute-force attacks, with its security calculations widely cited in cryptography literature.
Did You Know?
- The original Diceware word list contains 7,776 unique words, one for each possible five-die combination.
- Each word in a Diceware passphrase adds 12.9 bits of entropy, calculated as log2(6^5).
- In 2014, creator Arnold Reinhold increased the recommended minimum from five words to six words.
- The Electronic Frontier Foundation published three alternative English Diceware word lists in 2016.
The Dice-to-Word Pipeline
Diceware transforms the humble six-sided die into a practical cryptographic tool. The procedure is deceptively simple: roll the die five times, record each face as a digit, and you obtain a five-digit number. That number serves as an index into a fixed word list containing exactly 7,776 entries—one for every possible combination of five rolls. In the original list, the sequence 43146 maps to the word "munch." Repeat the five-roll procedure as many times as desired, and a string of random, memorable words assembles itself into a passphrase. No computer, no software, no internet connection is required; the randomness comes entirely from the physical act of tumbling a die. This makes Diceware a genuine hardware random number generator, one that any person with a single die and a printed list can operate. The method's elegance lies in its transparency: the entire mechanism is visible, reproducible, and free of proprietary components.
Measuring Unpredictability
The security of a Diceware passphrase can be quantified with straightforward mathematics. Each word contributes log₂(6⁵) bits of entropy, which works out to approximately 12.9 bits. Arnold Reinhold, the method's creator, originally recommended five words in 1995, yielding roughly 64.6 bits of total unpredictability. By 2014, however, he raised the minimum to six words, pushing the total to about 77.5 bits. These figures rest on a specific threat model: the calculation assumes an attacker already knows that Diceware was used, knows which word list was chosen, and knows the exact word count. If any of those facts remain hidden, the effective entropy per word exceeds 12.9 bits. One subtle requirement also affects the math: words must be separated by a space or other non-letter character. If they are simply concatenated, redundancy creeps in—phrases like "in put clammy" and "input clam my" collapse into the same string—slightly reducing the calculated entropy.
The Word List Ecosystem
A Diceware word list is not a secret. Its entire contents can be public, because the security of the passphrase depends on the number of words chosen and the size of the list from which each word was drawn, not on hiding the list itself. The standard requirement is 7,776 unique words—exactly enough to cover every five-roll combination. Lists have been compiled in more than two dozen languages, making the method accessible far beyond English speakers. In 2016, the Electronic Frontier Foundation released three alternative English lists that prioritize ease of memorization, deliberately steering away from obscure, abstract, or otherwise problematic vocabulary. The tradeoff is practical: typical EFF-style passphrases demand typing more characters than their original-list counterparts. Example passphrases from the original list read like "dobbs bella bump flash begin ansi," while EFF examples include longer, more descriptive words such as "conjoined sterling securely chitchat spinout pelvis."
Cultural Resonance & Neighboring Systems
Diceware occupies a distinctive niche in the broader landscape of password and key management. Its philosophy—human-readable words generated by a physical random source—echoes in several neighboring systems. The PGP biometric word list, for instance, uses two lists of 256 words where each word encodes eight bits, while S/KEY maps 64-bit numbers onto six English words drawn from a 2,048-word list. Diceware's 7,776-word structure sits between these approaches in granularity. The method also crossed into popular culture: the XKCD comic strip #936 depicts a password that closely resembles a Diceware-style passphrase, even though the strip's word list is shorter than the full 7,776-entry standard. Reinhold's original 1995 design has endured for nearly three decades, referenced in publications like John R. Levine's Internet Secrets (2nd Edition, 2000), and remains a touchstone for anyone seeking a transparent, software-free path to strong authentication.
Frequently Asked Questions
What is Diceware?
Diceware is a passphrase-generation technique that treats a standard six-sided die as a physical random-number source. Rather than typing random characters, you roll the die five times to build a five-digit index and then pick the matching word from a fixed list.
Who created Diceware and when?
Arnold Reinhold devised the method in 1995 as a practical way for non-experts to produce cryptographically strong secrets. It sits at the intersection of cryptography and everyday hobbyist tools.
How does the Diceware method actually work?
You roll a single d6 five times, read the results as a five-digit number, and use that number to select a word from a predefined word list. Repeating the process for at least five words yields a passphrase carrying roughly 64.6 bits of entropy.
How many words are in the Diceware word list?
The original English list contains exactly 7,776 entries, which equals 6 to the fifth power, so every possible five-roll sequence maps to one unique word. Translated lists have since been compiled in more than two dozen languages.
Why is Diceware considered important in the security community?
It demonstrates that a simple analog tool—a single die—can produce randomness genuinely unpredictable to any adversary. Each word contributes about 12.9 bits of entropy, making brute-force attacks infeasible without any electronic hardware.
More in Dice 1-21
Spotted an error? Know more?
This is a living reference — every entry is fact-audited, and reader corrections feed straight into our audit queue. Suggest an edit · See this site's audit record
