How to generate a strong password
- 1.
Choose the type
“Random password” is ideal for a password manager. “Passphrase” is easier to remember and type, good for a master password or a laptop login.
- 2.
Set length and characters
For random passwords pick the length (16+ recommended) and character sets. For passphrases pick the number of words (7+), separator and options.
- 3.
Check the strength
Entropy in bits and the estimated time to crack update instantly as you change the settings.
- 4.
Copy the password
Copy it into your password manager. Need a different one? Click “Generate new”.
How password strength is measured
The strength of a random password is its entropy in bits: E = L × log₂(N), where L is the length and N the number of possible characters. Every extra bit doubles the number of guesses an attacker needs.
| Password | Pool N | Entropy | Average time to crack* |
|---|---|---|---|
| PIN, 4 digits | 10 | 13.3 bits | instantly |
| 8 lowercase letters | 26 | 37.6 bits | about 10 s |
| 12 chars: letters + digits | 62 | 71.5 bits | about 5,000 years |
| 16 chars: all sets | 90 | 103.9 bits | about 2.9 × 1013 years |
| 7 English words + digit | 378 words | 66.1 bits | about 120 years |
* at 10 billion guesses per second - a realistic rate for an offline attack on a leaked database hashed with a fast function (MD5, SHA-1) using a few graphics cards. Sites that use bcrypt or Argon2 slow such attacks down by thousands of times.
What makes this generator safe
- Cryptographic randomness - characters are picked with
crypto.getRandomValues(), the browser’s CSPRNG, not the predictableMath.random(). - No modulo bias - a naive
random % Nmakes some characters slightly more likely. The generator uses rejection sampling, so every character has exactly the same chance. - Every set at least once - the password contains at least one character from each selected set, and positions are shuffled with the Fisher-Yates algorithm.
- Optional look-alike exclusion - drop I, l, 1, |, O, 0 and o when a password must be read aloud or typed from paper.
- Fully local - nothing is sent, logged or stored. The tool keeps working offline.
Passphrases and current NIST guidance
A passphrase is a string of randomly chosen words, such as Comet-Pumpkin-Harbor-Winter4-Teapot-Otter-Satchel. It is longer but far easier to remember and to type on a phone. The English word list has 378 common, easy-to-spell words, which gives about 8.6 bits per word, so choose 7 or more words for strong protection. What matters is that the generator picks the words, not you: human-chosen phrases like “ILoveMyDog2026” are predictable and appear in cracking dictionaries.
Current NIST guidance (SP 800-63B) favours length over complexity rules: at least 15 characters when a password is the only factor, no forced periodic changes, and a check against known breached passwords. Use a unique password for every site - a password manager makes that practical - and turn on two-factor authentication wherever you can.
Need random identifiers instead of secrets? Use the UUID generator.
Frequently asked questions
Are the generated passwords saved or sent anywhere?
+
How long should a password be?
+
What is password entropy?
+
Random password or passphrase - which is better?
+
Can I generate a numeric PIN?
+
Why not just use Math.random()?
+
Updated: