Technologies K–10 · Years 5–6

Dice passphrases: why four random words beat one clever password

Digital Technologies: Processes and production skills, Privacy and security (ACARA v9); no NSW code: neither the Science and Technology K–6 Syllabus (2017) nor the 2024 syllabus has a Stage 3 content point on passwords or passphrases

Practical, model not builtLow risk

This site has no interactive model of its own. Where a step or a material names a Concept Studio model, simulation or tool, it has not been built; an external simulation a step names (for example PhET) is not part of this site.

The idea

A passphrase of words chosen by rolling dice is easy to remember yet has so many possible combinations that guessing it takes far longer than guessing a short password, and reusing it anywhere undoes that protection.

What you need

  • 5 six-sided dice per group
  • A printed dice word list of 7,776 words numbered 11111 to 66666 (the EFF long word list)
  • Calculator

How to do it

  1. Roll 5 dice, read them left to right as a 5-digit number and look up the word. Repeat until you have 4 words.
  2. Work out how many different words 5 dice can pick: 6 × 6 × 6 × 6 × 6.
  3. Work out how many 4-word passphrases are possible and how many 8-letter lowercase passwords are possible.
  4. Using an assumed guessing speed of one billion guesses per second, work out the longest time to guess each.
  5. Discuss what happens if the same passphrase is used on two websites and one of them is broken into.
  6. Because the class passphrases were shared aloud, do not use them for any real account.

What you should see

5 dice give 7,776 words. 4 words give 3,656,158,440,062,976 passphrases (about 3.66 × 10¹⁵) and 8 lowercase letters give 208,827,064,576 passwords (about 2.09 × 10¹¹), so the passphrase has about 17,508 times more possibilities. At the assumed one billion guesses per second, every 8-letter password is tried in 208.8 s, every 4-word passphrase in 42.3 days and every 5-word passphrase in about 901 years. The Australian Cyber Security Centre recommends four or more random words, and a different passphrase for each account, because a passphrase stolen from one website is tried on others. The learner knows it worked when their numbers match these.

What changes

This activity lists no variables to change, measure and keep the same.

Common misconceptions

Each of these ideas is wrong, and the activity is a chance to test it.

  • Swapping letters for symbols (p@ssw0rd) makes a password strong (guessing programs try those swaps first).
  • A long password is hard to remember so short ones are better (a few random words are both long and memorable).
  • Using one strong password everywhere is safe (one leak exposes every account).

Safety card

Low riskLearners carry it out

Hazards

  • Passphrases made in class are known to others

Controls

  • Class passphrases are practice only and are never used for real accounts

Note

No chemicals or heat.

Curriculum references

The NSW syllabus outcomes and Australian Curriculum v9 codes this activity supports. They are references, not a verified or complete curriculum alignment.

  • No NSW syllabus code is listed.
  • Australian Curriculum v9AC9TDI6P09

Sources

The pages the author read to write this activity.

  1. www.nsw.gov.au/education-and-training/nesa/curriculum/science/science-and-technology-k-6-2017
  2. curriculum.nsw.edu.au/learning-areas/science/science-and-technology-k-6-2024/outcomes
  3. www.cyber.gov.au/protect-yourself/securing-your-accounts/passphrases
  4. www.eff.org/dice
  5. www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases
  6. curriculum.nsw.edu.au/learning-areas/science/science-and-technology-k-6-2024/content/stage-3/fa9723a7dc

All Concept Studio activities