/tools/security

๐Ÿ” Security & Generators

Generators built on your browser's cryptographic random source rather than Math.random, with the entropy stated so you can judge the strength yourself.

3 of 3

About security & generators

Anything generating a secret must do it locally, and must do it properly. Both halves matter. A password generated on a server has been transmitted before you ever see it. A password generated from a weak random source is predictable no matter how long it is.

The tools here use crypto.getRandomValues, which draws on entropy collected by your operating system, and they use rejection sampling to avoid the modulo bias that skews most quick implementations. Nothing makes a network request โ€” you can disconnect and generate offline to verify it.

Where a number is shown โ€” bits of entropy, an estimated crack time โ€” the assumptions behind it are stated, because a coloured strength bar with no explanation tells you nothing useful.

Most used in this category

Other categories