Password Generator

Build a strong random password or a memorable passphrase, generated in your browser and never transmitted.

—

Very strong129 bits

An attacker guessing 10 billion times a second would need longer than the universe has existed to find this.

20

Processed on your device. This file is never uploaded.

  1. 1Choose a password or a passphrase.
  2. 2Set the length and which characters to include.
  3. 3Copy it — and store it in a password manager rather than reusing it.

Where the randomness comes from

Every password here is drawn from crypto.getRandomValues, your browser's cryptographically secure random number generator. That distinction matters: the more familiar Math.random is seeded from a source that is fast, predictable in some engines, and entirely unsuitable for anything protecting an account.

Characters are also selected by rejection sampling rather than by taking a random number modulo the alphabet size. The modulo approach quietly makes the first few characters of the alphabet slightly more likely than the rest — a small bias, but an avoidable one, and avoiding it is the entire job of a password generator.

Length beats complexity

Adding one character to a password multiplies the search space by the size of the alphabet. Adding a symbol to a short password multiplies it once. This is why a sixteen-character lowercase password is dramatically stronger than an eight-character one sprinkled with punctuation, and why the length slider matters more than any of the toggles beneath it.

What the crack time really means

The estimate assumes ten billion guesses per second — an offline attack against a poorly hashed password database using ordinary graphics hardware. It is deliberately pessimistic. A service storing passwords properly, with bcrypt or Argon2, slows an attacker by several orders of magnitude. A password that survives the figure shown here survives the realistic cases comfortably.

Generating it is the easy half

A strong password reused across three sites is weaker than a mediocre one used nowhere else, because the breach of any one site hands over the other two. Put these in a password manager. The point of a generated password is that you never need to remember it — only the one passphrase that unlocks the vault.

Frequently asked questions