What is Diceware?
A method for making passphrases that are truly random and actually memorable, using nothing but dice and a numbered word list — no software, no algorithms you can't verify, no trusting a computer. This book is the word list: the EFF's Long Wordlist, all 7,776 words of it, one for every possible roll of five dice.
-
Take five dice into a room with no cameras, microphones, or windows.
The point of Diceware is that no computer ever sees, stores, or transmits your passphrase while it's being made.
-
Roll all five, place them in any order, and look up the number.
52614 salsaEach five-digit number matches exactly one word in the book. That word is the next part of your passphrase.
-
Repeat until you have enough words.
Write them on a single sheet of paper on a hard surface — don't use a pad of paper, and don't mark the book. Six rolls might give you:
salsahandedcleatsynopsispaybackexpert
More background at eff.org/dice.
How many words are enough?
Six words is the recommended safe minimum as of 2026 for most common uses: Wi-Fi passwords, encrypted email, whole-disk encryption. Seven words is more appropriate for protecting any store of money — bank accounts, brokerages, cryptocurrency wallets.
Solid/dotted lines: a stolen copy of your data, cracked on an eight-GPU rig against an unsalted SHA-1 hash, with projections past 2026. Dashed line: guesses sent over a network at 1,000 attempts per second — a rate capped by the service, not the attacker's hardware.
See the data as a table
| Year | Hardware (8-GPU rig) | 5 words | 6 words | 7 words | 5 words, online |
|---|---|---|---|---|---|
| 2017 | 8× GTX 1080 Ti · 92 GH/s | 4.9 years | 38,000 years | 300 million years | 450 million years |
| 2020 | 8× RTX 3090 · 182 GH/s | 2.5 years | 19,000 years | 150 million years | 450 million years |
| 2022 | 8× RTX 4090 · 405 GH/s | 1.1 years | 8,600 years | 67 million years | 450 million years |
| 2026 | 8× RTX 5090 · 562 GH/s | ≈10 months | 6,200 years | 48 million years | 450 million years |
| 2035 (projected) | ≈4× the 2026 flagship | ≈10 weeks | 1,600 years | 12 million years | 450 million years |
If an attacker must guess over the network, against a service that allows about 1,000 attempts per second, working through half the five-word possibilities takes about 450 million years — and faster computers don't shorten it, because the service sets the pace.
The picture changes if they steal a copy of your data and attack it on their own hardware. In 2026, an eight-GPU array of NVIDIA RTX 5090s — roughly $30,000 of hardware — manages about 560 billion guesses per second against a fast, unsalted hash like SHA-1. At that rate, half of all five-word phrases fall in about ten months. The same rig would need some 6,000 years for a six-word phrase, and 48 million years for seven.
Hardware keeps improving, so think a decade ahead: by 2035 that five-word attack may take only ten weeks. Simply adding a sixth word raises the projected 2035 attack to 1,600 years.
Assumes an unsalted SHA-1 hash — close to a worst case. Systems that use key-stretching algorithms like bcrypt or Argon2 are orders of magnitude slower to attack. GPU gains have been flattening; the projection assumes only about a 4× speedup from 2026 to 2035.
Why a printed book?
Sure, you could download the list and scroll around on a screen, or print it on your inkjet. The book is better:
-
It's a real book
Easier to use, store, and carry than loose printouts — and a hardcopy keeps your computer completely out of the password-making process, which is the whole spirit of the thing.
-
It's compact
105 × 152 mm — about the size of a Beatrix Potter book or a Hobonichi planner. It fits in one hand and flips easily.
-
It's cheap, and it funds the EFF
Half of all profits are donated to the Electronic Frontier Foundation — not because they asked, but because they deserve it.
-
It's carefully typeset
Set in Taurus Grotesk and Halyard Micro, a typeface designed for reference texts and tabular data. Dice-style running heads help you flip to the right page, and a visual break marks every change in the second digit — see the page samples at left.
What dice should I use?
Here's something most people don't know: ordinary dice are biased. Any large sample of rolls from common gaming dice yields about 30% ones — nearly twice what a truly random die would produce.
The reason is cost-cutting. Pips are carved out of the die's faces, so the six side — with more material removed — is lighter than the one side, and rounded corners let that imbalance steer the roll. Manufacturers recover enough plastic from the pips and corners of two dice to make a third.
For truly random rolls, use clear, square-cornered casino dice from a supplier like Midwest Game Supply or Paulson. Their pips are filled with material of the same density as the body, and the translucent resin lets you check for air bubbles yourself.
Only precision dice are truly random.
Questions people actually ask
If I buy this book, won't the government know exactly how I make my passwords?
Probably! But the beauty of the system is that it doesn't matter. Even if an attacker knows the exact list you used and exactly how many words you rolled, they still face the full space of possible combinations — 28 quintillion of them for even a five-word phrase. The secrecy lives entirely in the dice rolls, not in the method.
Won't quantum computing break all encryption soon anyway?
Short answer: no. Picking strong passphrases will still matter in a post-quantum world. Quantum computers may eventually break some asymmetric encryption (like RSA), and the software world is already migrating to post-quantum algorithms. Symmetric encryption and hashed passphrases are a different story: the only relevant quantum method, Grover's algorithm, effectively halves a key's strength against brute force — which makes a longer passphrase more important, not less. A six-word phrase leaves you safe even after that halving.
Is it legal to sell the EFF's word list?
Yes! The EFF publishes the list under the CC-BY 3.0 license, which allows commercial redistribution — and they confirmed this to me by email before the first edition. Donating half the profits back to them is my own idea, not their request.
I don't like Amazon. Can I order directly?
You sure can. Email me at joeld@protonmail.com with your address and preferred payment method and we'll work something out. It takes a little longer, but you probably knew that.
What's new in the second edition?
The crack-time research and chart are fully updated for 2026 hardware (and its flattening growth curve), there's a new section on quantum computing, the interior was redesigned and regenerated with Typst, and the cover is new. The word list itself is unchanged — it's still the EFF's Long Wordlist, so a first edition remains perfectly usable.
Where did dice word lists come from?
Arnold Reinhold compiled the original Diceware list in 1995, capping words at six letters for typing convenience — which forced in many rare words, names, and letter sequences. In 2016 the EFF published a new list built on word-frequency data from Ghent University's Center for Reading Research, designed to be easier to memorize, spell, and tell apart. That's the list in this book.