What makes a password strong?
Password strength comes from length and randomness. Each extra character multiplies the number of guesses an attacker needs, so a random 16-character password with letters, numbers and symbols has about 100 bits of entropy and is far beyond brute force. This generator uses the browser Web Crypto API (crypto.getRandomValues) with unbiased sampling, which is suitable for security-sensitive use, unlike Math.random.
Features
- • Cryptographically secure randomness with no modulo bias
- • Length from 4 to 128, up to 20 passwords at once
- • Every selected character type is guaranteed to appear
- • Exclude look-alike or custom characters
- • Entropy, strength and brute-force time estimate, plus a checker for existing passwords
Generated locally
Passwords are created in your browser and are never sent, logged or stored anywhere. You can disconnect from the internet after the page loads and the generator keeps working.