# Word lists of `wordkey.Generate`
The lists from which `datekeys encrypt -new-words` draws a key of words at
random (spec §38.1: at least 6 words of a public list of 2048 or more). They
are not normative: a reader does not need them, because the key is derived
from the normalized text of the words, whatever list they came from.
| List | Words | SHA-256 | Status |
|---|---|---|---|
The English list: the large wordlist of the EFF, and -dic en by default
wordkey/lists/en.txt is the large wordlist for passphrases of the EFF,
7776 words, CC BY 4.0 under its copyright policy, without the dice number
of each line and in its order, so that the position of a word still gives
its dice, 11111 for the first. encrypt -new-words takes it by default, as
the author decided; -dic es takes the Spanish one. The alphabet of en is a
to z and the ASCII hyphen of its four compound words, such as t-shirt,
kept so that no word loses its dice. lists/README.md records its source,
the SHA-256 of the download, the change and the license.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
11 hours ago
| `en.txt` | 7776 | `6d557f0693958fb5e650b68b5bee585eb82cf4da32965505c789e924743bc522` | The large wordlist of the EFF, as published |
| `es.txt` | 7776 | `ff77b487765c000da97cca58fe94a2cdb947303e7a07460614d7d95d800034fe` | Draft, not yet reviewed by a native speaker |
The English list: the large wordlist of the EFF, and -dic en by default
wordkey/lists/en.txt is the large wordlist for passphrases of the EFF,
7776 words, CC BY 4.0 under its copyright policy, without the dice number
of each line and in its order, so that the position of a word still gives
its dice, 11111 for the first. encrypt -new-words takes it by default, as
the author decided; -dic es takes the Spanish one. The alphabet of en is a
to z and the ASCII hyphen of its four compound words, such as t-shirt,
kept so that no word loses its dice. lists/README.md records its source,
the SHA-256 of the download, the change and the license.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
11 hours ago
Each list has 7776 = 6^5 words, sorted, so that five dice give a word: each
die minus one is a digit of the position of the word in base 6, the first
die the most significant. The dice 11111 give the first word and 66666 the
Dice: the words of five dice each, encrypt -dice and datekeys wordlist
For whoever does not trust the random numbers of a computer, as the author
decided: five dice for each word, read in a fixed order, give a number
from 11111 to 66666, the position of the word in a list of 7776 words, the
first die the most significant. wordkey.DiceNumber and DiceWord number the
words and give the word of a number; DiceWords takes several numbers, at
least 6 and never the same word twice, which is rolled again; DiceList is
the list numbered for dice, a line for each word with its dice and a tab,
as the EFF publishes its own: for en it is the file of the EFF, byte for
byte.
encrypt -dice TEXT and -dice-file FILE take the words from the dice of the
list -dic and show them: the words open the capsule, the numbers give them
only with that list. datekeys wordlist [-dic LIST] writes the numbered
list, to print it, and its SHA-256, which wordkey/lists/README.md records.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
10 hours ago
last, as in the list of the EFF. `datekeys wordlist` (`wordkey.DiceList`)
writes a list numbered for dice, to print it: a line for each word, its
dice, a tab and the word, as the EFF publishes its list.
| List numbered for dice | SHA-256 |
|---|---|
| `en` | `addd35536511597a02fa0a9ff1e5284677b8883b83e986e43f15a3db996b903e` , the file of the EFF, byte for byte |
| `es` | `611f779a33df74587e9dfb486bb0185a9dfd4d1384e75993a21247ad31cefddb` |
The English list: the large wordlist of the EFF, and -dic en by default
wordkey/lists/en.txt is the large wordlist for passphrases of the EFF,
7776 words, CC BY 4.0 under its copyright policy, without the dice number
of each line and in its order, so that the position of a word still gives
its dice, 11111 for the first. encrypt -new-words takes it by default, as
the author decided; -dic es takes the Spanish one. The alphabet of en is a
to z and the ASCII hyphen of its four compound words, such as t-shirt,
kept so that no word loses its dice. lists/README.md records its source,
the SHA-256 of the download, the change and the license.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
11 hours ago
A list changes only with its hash in this file and in `generate_test.go` :
an application that downloads a list pins its SHA-256 and refuses any other.
The alphabet of a word list and the strength of the words drawn
wordkey.CheckList takes the language of the list and refuses a word with a
character that is not a letter of its alphabet, which only the code gives:
for es, a to z, the five vowels with an acute accent, u with diaeresis and
n with tilde, in lower case and NFC. A Cyrillic letter that looks like a
Latin one, a capital, a digit or the carriage return of a file with CRLF
lines would be written down and typed again with another character, and
the capsule would not open. The Spanish list passes as it is; its SHA-256
does not change.
wordkey.Bits is the strength of the words that Generate draws, log2 of the
number of draws in order, and encrypt -new-words prints it: 90 bits for 7
words of 7776.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
12 hours ago
`wordkey.CheckList` checks a list against the alphabet of its language,
which the code gives and not the list: a word with a letter of another script
that looks the same, such as a Cyrillic `а ` (U+0430) for a Latin `a` , would be
typed again with the letter of the keyboard, and the capsule would not open.
| Language | Alphabet |
|---|---|
The English list: the large wordlist of the EFF, and -dic en by default
wordkey/lists/en.txt is the large wordlist for passphrases of the EFF,
7776 words, CC BY 4.0 under its copyright policy, without the dice number
of each line and in its order, so that the position of a word still gives
its dice, 11111 for the first. encrypt -new-words takes it by default, as
the author decided; -dic es takes the Spanish one. The alphabet of en is a
to z and the ASCII hyphen of its four compound words, such as t-shirt,
kept so that no word loses its dice. lists/README.md records its source,
the SHA-256 of the download, the change and the license.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
11 hours ago
| `en` | `a` to `z` and the ASCII hyphen of the four compound words of the list of the EFF (`drop-down`, `felt-tip` , `t-shirt` and `yo-yo` ), in lower case |
The alphabet of a word list and the strength of the words drawn
wordkey.CheckList takes the language of the list and refuses a word with a
character that is not a letter of its alphabet, which only the code gives:
for es, a to z, the five vowels with an acute accent, u with diaeresis and
n with tilde, in lower case and NFC. A Cyrillic letter that looks like a
Latin one, a capital, a digit or the carriage return of a file with CRLF
lines would be written down and typed again with another character, and
the capsule would not open. The Spanish list passes as it is; its SHA-256
does not change.
wordkey.Bits is the strength of the words that Generate draws, log2 of the
number of draws in order, and encrypt -new-words prints it: 90 bits for 7
words of 7776.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
12 hours ago
| `es` | `a` to `z` , `á` , `é` , `í` , `ó` , `ú` , `ü` and `ñ` , in lower case and NFC |
The English list: the large wordlist of the EFF, and -dic en by default
wordkey/lists/en.txt is the large wordlist for passphrases of the EFF,
7776 words, CC BY 4.0 under its copyright policy, without the dice number
of each line and in its order, so that the position of a word still gives
its dice, 11111 for the first. encrypt -new-words takes it by default, as
the author decided; -dic es takes the Spanish one. The alphabet of en is a
to z and the ASCII hyphen of its four compound words, such as t-shirt,
kept so that no word loses its dice. lists/README.md records its source,
the SHA-256 of the download, the change and the license.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
11 hours ago
## `en.txt`
- **Source:** the large wordlist for passphrases of the Electronic Frontier
Foundation, by Joseph Bonneau (2016),
< https: / / www . eff . org / files / 2016 / 07 / 18 / eff_large_wordlist . txt > , whose
SHA-256 was
`addd35536511597a02fa0a9ff1e5284677b8883b83e986e43f15a3db996b903e` when
it was downloaded on 7 October 2026. The EFF explains it in
< https: / / www . eff . org / deeplinks / 2016 / 07 / new-wordlists-random-passphrases > .
- **License:** original material of the EFF, which its
[copyright policy ](https://www.eff.org/copyright ) licenses under
[CC BY 4.0 ](https://creativecommons.org/licenses/by/4.0/ ), unlike the code
of this module (Apache 2.0).
- **Change:** the dice number before each word is left out, and nothing
else: the words and their order are those of the EFF, so the position of a
word still gives its number.
## `es.txt`
- **Source:** the frequencies of
[FrequencyWords ](https://github.com/hermitdave/FrequencyWords ) by Hermit
Dave, `content/2018/es/es_50k.txt` , counted on the OpenSubtitles 2018
corpus, licensed under CC BY-SA 4.0. The Spanish Hunspell dictionary of
LibreOffice (RLA-ES, `es_ES.dic` and `es_ES.aff` ) is used only as a filter
and is not redistributed.
- **License:** this list is an adaptation of FrequencyWords and is licensed
under [CC BY-SA 4.0 ](https://creativecommons.org/licenses/by-sa/4.0/ ),
unlike the code of this module (Apache 2.0).
- **Method:** the most frequent words that are, in order:
1. lowercase letters only, of 3 to 9 letters;
2. a base form of the dictionary: an entry with affix flags, or the
feminine its flag `G` makes. Entries without flags, which are
conjugations, plurals and pieces of names, are left out;
3. not in a short list of offensive or unpleasant words;
4. not the other half of a pair that differs only in a final `-o` or `-a`
(`chico` and `chica` ): the more frequent stays;
5. not the same as a word already taken once normalized as in §38.1
(`papa` and `papá` ): the more frequent stays.
The alphabet of a word list and the strength of the words drawn
wordkey.CheckList takes the language of the list and refuses a word with a
character that is not a letter of its alphabet, which only the code gives:
for es, a to z, the five vowels with an acute accent, u with diaeresis and
n with tilde, in lower case and NFC. A Cyrillic letter that looks like a
Latin one, a capital, a digit or the carriage return of a file with CRLF
lines would be written down and typed again with another character, and
the capsule would not open. The Spanish list passes as it is; its SHA-256
does not change.
wordkey.Bits is the strength of the words that Generate draws, log2 of the
number of draws in order, and encrypt -new-words prints it: 90 bits for 7
words of 7776.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
12 hours ago
The first 7776 that pass, sorted. `wordkey.CheckList` checks the last rule,
the characters of every word and the alphabet.