Human-chosen passwords are predictable in ways that are easy to exploit — names, dates, keyboard patterns, a word with a digit on the end. Attackers model these patterns directly. A genuinely random password has no pattern to model, which is the entire point.
How to use the Password Generator
- Set the length — 16 characters or more for anything that matters
- Choose which character types to include
- Generate, then copy the password straight into your password manager
- Use a different password for every account
Length matters more than complexity
Each additional character multiplies the search space. Each additional character type only widens the base. Length wins decisively.
Using all four character types (95 possible characters):
- 8 characters — about 52 bits of entropy. Crackable by a well-resourced attacker.
- 12 characters — about 79 bits. Reasonable for most accounts.
- 16 characters — about 105 bits. The current sensible minimum for anything important.
- 24 characters — about 158 bits. Beyond any foreseeable brute-force capability.
This is why the old advice — eight characters with a capital, a number and a symbol — is obsolete. It produces passwords that are both hard to remember and inadequate. NIST dropped mandatory complexity rules and composition requirements in 2017 precisely because they pushed people toward predictable substitutions like P@ssw0rd1.
Randomness has to be real
This generator uses crypto.getRandomValues(), the browser's cryptographically secure random number generator — the same primitive used for TLS key material.
The alternative, Math.random(), is not cryptographically secure. It is fast and statistically fine for shuffling a list; it is predictable enough that an attacker who observes some output can infer the rest. Password generators built on it have been broken in practice. If you use a different generator, check which source it uses.
Nothing generated here is transmitted or stored — generation is entirely local, which you can verify by disconnecting from the network and watching it still work.
Frequently asked questions
Are these passwords truly random?
Yes. They use crypto.getRandomValues(), the browser's CSPRNG — the same source used for cryptographic keys, not the predictable Math.random().
Are generated passwords stored or sent anywhere?
No. Generation happens entirely in your browser and nothing is transmitted or logged. The page works with the network disconnected, which you can test.
How long should a password be?
At least 16 characters for important accounts, 20 or more for anything critical such as your email or password manager master password. Length contributes far more than character variety.
Should I use a passphrase instead?
For passwords you must memorise — your device login and your password manager's master password — yes. Four or five random words give strong entropy and are far easier to recall. For everything else, use a generated random string stored in a manager.
Do I really need a different password everywhere?
Yes. Credential stuffing — replaying credentials leaked from one breach against other services — is among the most common attack methods. Reuse means one breach compromises every account sharing that password.