When generating a memorable passphrase using the Diceware method, the most common question is: how many words are actually enough?

Because humans are notoriously bad at intuitively understanding exponential math, people often assume that adding a single word slightly increases security, when in reality, it multiplies the difficulty for an attacker by the entire length of the dictionary.

This guide breaks down the exact entropy (measured in bits) of the widely used EFF Short Wordlist, and maps those bits to real-world cracking times across different hashing algorithms.

Calculating Diceware Entropy

The strength of a Diceware passphrase relies on two factors: the size of the dictionary, and the cryptographic randomness used to pick the words (which is why our Memorable Password Generator uses the browser’s native crypto.getRandomValues() instead of Math.random()).

In this guide, we assume the use of the EFF Short Wordlist.

  • Size: 1,296 words (calculated as 6⁴, since it relies on 4 rolls of a 6-sided die).
  • Entropy per word: log2(1296) = ~10.34 bits.

Every time you add a word to your passphrase, you add another 10.34 bits of entropy.

(Note: The EFF “Large” wordlist contains 7,776 words and provides ~12.92 bits per word. We focus on the Short list because it produces vastly more memorable passphrases with shorter, simpler words).

Crack Times by Hash Algorithm

Entropy bits alone are abstract. To understand security, we must map bits to Guesses Required, and then divide by the Guesses Per Second an attacker can compute.

The speed of an attack depends entirely on how the website hashed your password before storing it.

  • Fast Hashes (MD5, SHA1): A modern GPU cluster (e.g., 8x RTX 4090s) can calculate roughly 100 billion (10¹¹) hashes per second.
  • Slow Hashes (bcrypt, Argon2): These algorithms are intentionally designed to be computationally expensive. The same GPU cluster might only manage 100,000 to 1,000,000 (10⁵) hashes per second.

Here is how the math breaks down for a passphrase drawn from the EFF Short Wordlist:

Word CountEntropy (Bits)Total Possible CombinationsGPU Crack Time (MD5, Fast)GPU Crack Time (bcrypt, Slow)
4 Words41.4 bits2.8 Trillion29 seconds~335 days
5 Words51.7 bits3.6 Quadrillion10.2 hours~1,173 years
6 Words62.0 bits4.7 Quintillion1.4 years~1.4 Million years
7 Words72.4 bits6.0 Sextillion1,900 years~1.9 Billion years
8 Words82.7 bits7.7 Septillion2.4 Million years~2.4 Trillion years

The “correct horse battery staple” Trap

The famous XKCD #936 comic popularized the 4-word phrase correct horse battery staple. At the time of publication, it was considered highly secure.

However, as the table above shows, a 4-word passphrase is now dangerously vulnerable to offline dictionary attacks if the database uses a fast hash like MD5. Furthermore, because that specific phrase is so famous, it has been manually added to almost every hacker’s wordlist globally—meaning its true entropy is zero. (Never use that exact phrase).

Conversely, traditional “complex” passwords like Tr0ub4dor&3 (which substitute numbers and symbols for letters) often yield only ~28 bits of entropy. A GPU cluster can brute-force 28 bits in a fraction of a second.

So, How Many Words Should You Use?

The correct length depends entirely on your threat model and what the passphrase protects.

1. The 5 to 6 Word Sweet Spot (Standard Logins)

If you are generating a passphrase for a standard website account, 5 to 6 words is the mathematical sweet spot. If the site is breached and uses a modern hash like bcrypt, 51 bits of entropy is computationally infeasible to crack in a human lifetime.

If the site uses a negligent, fast hash like MD5, 6 words (62 bits) will stall a high-end GPU cluster for over a year, forcing the attacker to give up and move on to easier targets in the database dump.

2. The 7 to 8 Word Maximum (Master Passwords)

If you are generating a Master Password for your 1Password or Bitwarden vault, or generating a key to encrypt a local hard drive, you should use 7 to 8 words.

Your vault contains the keys to your entire digital life. Because offline brute-forcing technology (and eventually, quantum computing) will inevitably get faster over the next two decades, front-loading 72+ bits of entropy guarantees that your vault will remain locked even against well-funded, nation-state tier hardware architectures.

Diceware vs. Password Managers

You should not use Diceware for every single account you own.

  1. Use a single, high-entropy 8-word Diceware passphrase to lock your Password Manager. This secures your vault against offline attacks while remaining permanently etched in your human memory.
  2. Inside the vault, use your Password Manager to generate and autofill completely random, 32-character alphanumeric strings for every website you visit.

This completely eliminates password reuse while minimizing the cognitive load of memorizing multiple passphrases.