/tools/password-generator

Password Generator

Passwords built from your browser's cryptographic random source, with the entropy shown in bits so you can judge the strength rather than trust a coloured bar.

Password GeneratorRuns in your browser
Generated locally. Passwords are created in your browser with crypto.getRandomValues. Nothing is sent over the network, logged or stored anywhere.
Type

How to use the Password Generator

  1. Choose random characters for maximum strength per character, or a passphrase for something you can actually type.
  2. Set the length. For anything important, aim for at least 16 characters or 5 words.
  3. Press Generate, copy the result, and store it in a password manager rather than a note.

Entropy is the only meaningful measure

Password strength is measured in bits of entropy — the base-2 logarithm of how many equally likely passwords the generator could have produced. Each additional bit doubles the work an attacker faces.

BitsVerdict
Under 45Weak. Crackable by a determined attacker.
60–70Adequate for ordinary accounts.
80+Strong against any realistic offline attack.
128Beyond brute force with any foreseeable technology.

Entropy depends on the process, not the result. Tr0ub4dor&3 looks random but came from a predictable substitution pattern. A password you invented has far less entropy than its length suggests, because human choices cluster.

Passphrases and the maths behind them

A passphrase of five words drawn randomly from a list of a thousand has 1000⁵ possibilities — about 50 bits. Add a random number and it climbs further. That is comparable to a shorter random string, but vastly easier to type on a phone or read aloud.

The critical word is randomly. A phrase you chose yourself — a song lyric, a quotation, a sentence about your life — has almost no entropy, because attackers have compiled those. Only machine-generated word selection gives you the number above.

Practical advice that matters more than length

  • Never reuse a password. Credential stuffing — trying leaked passwords on other sites — succeeds far more often than cracking does. A unique password per site limits any breach to one account.
  • Use a password manager. It is the only realistic way to have unique strong passwords everywhere. Protect it with a long passphrase you have memorised.
  • Turn on two-factor authentication. It defeats a stolen password entirely. An authenticator app or hardware key beats SMS, which is vulnerable to SIM swapping.
  • Stop rotating passwords on a schedule. Modern guidance from NIST advises against forced periodic changes — they push people towards predictable variations. Change a password when there is reason to think it was exposed.

Frequently asked questions

Is it safe to generate a password on a website?

It depends entirely on where generation happens. Here it runs in your browser via crypto.getRandomValues, with no network request — you can verify this by checking your browser's network tab, or by disconnecting and generating offline.

How long should a password be?

At least 16 random characters, or 5 random words, for anything that matters. For a password manager master password, go longer — it protects everything else.

Are symbols necessary?

They add roughly one bit per character over letters and digits alone. Length is the stronger lever: a longer alphanumeric password beats a short one full of symbols, and it will not be rejected by sites with restrictive rules.

What does the crack time estimate assume?

A hundred billion guesses per second — a well-resourced offline attack against a fast hash. Against a properly slow algorithm like Argon2 or bcrypt it would take far longer. It is a rough floor, not a guarantee.

Should I write the password down?

A password manager is better. But a note kept physically secure is genuinely better than reusing a weak password everywhere — the realistic threat to most people is remote, not someone searching their home.

Related tools