Password Generator
Passwords built from your browser's cryptographic random source, with the entropy shown in bits so you can judge the strength rather than trust a coloured bar.
crypto.getRandomValues. Nothing is sent over the network, logged or stored anywhere.How to use the Password Generator
- Choose random characters for maximum strength per character, or a passphrase for something you can actually type.
- Set the length. For anything important, aim for at least 16 characters or 5 words.
- Press Generate, copy the result, and store it in a password manager rather than a note.
Entropy is the only meaningful measure
Password strength is measured in bits of entropy — the base-2 logarithm of how many equally likely passwords the generator could have produced. Each additional bit doubles the work an attacker faces.
| Bits | Verdict |
|---|---|
| Under 45 | Weak. Crackable by a determined attacker. |
| 60–70 | Adequate for ordinary accounts. |
| 80+ | Strong against any realistic offline attack. |
| 128 | Beyond brute force with any foreseeable technology. |
Entropy depends on the process, not the result. Tr0ub4dor&3 looks random but came from a predictable substitution pattern. A password you invented has far less entropy than its length suggests, because human choices cluster.
Passphrases and the maths behind them
A passphrase of five words drawn randomly from a list of a thousand has 1000⁵ possibilities — about 50 bits. Add a random number and it climbs further. That is comparable to a shorter random string, but vastly easier to type on a phone or read aloud.
The critical word is randomly. A phrase you chose yourself — a song lyric, a quotation, a sentence about your life — has almost no entropy, because attackers have compiled those. Only machine-generated word selection gives you the number above.
Practical advice that matters more than length
- Never reuse a password. Credential stuffing — trying leaked passwords on other sites — succeeds far more often than cracking does. A unique password per site limits any breach to one account.
- Use a password manager. It is the only realistic way to have unique strong passwords everywhere. Protect it with a long passphrase you have memorised.
- Turn on two-factor authentication. It defeats a stolen password entirely. An authenticator app or hardware key beats SMS, which is vulnerable to SIM swapping.
- Stop rotating passwords on a schedule. Modern guidance from NIST advises against forced periodic changes — they push people towards predictable variations. Change a password when there is reason to think it was exposed.
Frequently asked questions
Is it safe to generate a password on a website?
It depends entirely on where generation happens. Here it runs in your browser via crypto.getRandomValues, with no network request — you can verify this by checking your browser's network tab, or by disconnecting and generating offline.
How long should a password be?
At least 16 random characters, or 5 random words, for anything that matters. For a password manager master password, go longer — it protects everything else.
Are symbols necessary?
They add roughly one bit per character over letters and digits alone. Length is the stronger lever: a longer alphanumeric password beats a short one full of symbols, and it will not be rejected by sites with restrictive rules.
What does the crack time estimate assume?
A hundred billion guesses per second — a well-resourced offline attack against a fast hash. Against a properly slow algorithm like Argon2 or bcrypt it would take far longer. It is a rough floor, not a guarantee.
Should I write the password down?
A password manager is better. But a note kept physically secure is genuinely better than reusing a weak password everywhere — the realistic threat to most people is remote, not someone searching their home.
Related tools
Generate SHA-256, SHA-384 and SHA-512 hashes of text or files.
Generate cryptographically random UUIDs in bulk.
Generate random numbers in a range, with or without repeats.
Encode text or files to Base64, with URL-safe output available.
Count characters against a limit, with a live countdown.