Skip to content
HNarzędzia
en
Categories

Strong password generator - random passwords and passphrases

Create secure passwords from letters, digits and symbols, or easy-to-type passphrases made of random English words. Every password is generated in your browser with crypto.getRandomValues() and never leaves your device.

  • Free
  • No sign-up
  • Private
  • Runs locally

Generated password

Strength
Very strong
Entropy
103.9 bits
Pool: 90 characters
Time to crack
over a trillion years
Average, at 10 billion guesses per second (offline attack on a fast hash).

How to generate a strong password

  1. 1.

    Choose the type

    “Random password” is ideal for a password manager. “Passphrase” is easier to remember and type, good for a master password or a laptop login.

  2. 2.

    Set length and characters

    For random passwords pick the length (16+ recommended) and character sets. For passphrases pick the number of words (7+), separator and options.

  3. 3.

    Check the strength

    Entropy in bits and the estimated time to crack update instantly as you change the settings.

  4. 4.

    Copy the password

    Copy it into your password manager. Need a different one? Click “Generate new”.

How password strength is measured

The strength of a random password is its entropy in bits: E = L × log₂(N), where L is the length and N the number of possible characters. Every extra bit doubles the number of guesses an attacker needs.

PasswordPool NEntropyAverage time to crack*
PIN, 4 digits1013.3 bitsinstantly
8 lowercase letters2637.6 bitsabout 10 s
12 chars: letters + digits6271.5 bitsabout 5,000 years
16 chars: all sets90103.9 bitsabout 2.9 × 1013 years
7 English words + digit378 words66.1 bitsabout 120 years

* at 10 billion guesses per second - a realistic rate for an offline attack on a leaked database hashed with a fast function (MD5, SHA-1) using a few graphics cards. Sites that use bcrypt or Argon2 slow such attacks down by thousands of times.

What makes this generator safe

  • Cryptographic randomness - characters are picked with crypto.getRandomValues(), the browser’s CSPRNG, not the predictable Math.random().
  • No modulo bias - a naive random % N makes some characters slightly more likely. The generator uses rejection sampling, so every character has exactly the same chance.
  • Every set at least once - the password contains at least one character from each selected set, and positions are shuffled with the Fisher-Yates algorithm.
  • Optional look-alike exclusion - drop I, l, 1, |, O, 0 and o when a password must be read aloud or typed from paper.
  • Fully local - nothing is sent, logged or stored. The tool keeps working offline.

Passphrases and current NIST guidance

A passphrase is a string of randomly chosen words, such as Comet-Pumpkin-Harbor-Winter4-Teapot-Otter-Satchel. It is longer but far easier to remember and to type on a phone. The English word list has 378 common, easy-to-spell words, which gives about 8.6 bits per word, so choose 7 or more words for strong protection. What matters is that the generator picks the words, not you: human-chosen phrases like “ILoveMyDog2026” are predictable and appear in cracking dictionaries.

Current NIST guidance (SP 800-63B) favours length over complexity rules: at least 15 characters when a password is the only factor, no forced periodic changes, and a check against known breached passwords. Use a unique password for every site - a password manager makes that practical - and turn on two-factor authentication wherever you can.

Need random identifiers instead of secrets? Use the UUID generator.

Frequently asked questions

Are the generated passwords saved or sent anywhere?

+
No. Passwords are created locally in your browser and are never sent or stored. The tool works even with your internet connection turned off.

How long should a password be?

+
For random passwords use at least 16 characters with all character sets (about 100 bits of entropy), and at least 12 for low-value accounts. A passphrase from this word list should have 7 or more words.

What is password entropy?

+
It measures unpredictability in bits: E = length × log₂(number of possible characters). A 60-bit password needs on average 2^59 guesses. Above 80-100 bits a password is practically impossible to brute-force.

Random password or passphrase - which is better?

+
A random password packs more security into each character and is perfect for a password manager. A passphrase is easier to remember, which makes it a good master password or device login.

Can I generate a numeric PIN?

+
Yes. Leave only “Digits” selected and set the length, for example 6. Remember a 4-digit PIN has only 10,000 combinations and is protected mainly by attempt limits.

Why not just use Math.random()?

+
Math.random() is not cryptographically secure and its output can be predicted. This generator uses crypto.getRandomValues(), which is designed for security purposes.

Updated: