Password Generator

Generated in your browser with the Web Crypto API, with look-alike characters (l, I, O, 0, 1) left out. Nothing is sent anywhere — and you can see exactly how much strength each character buys.

 
—bits of entropy

How long your password would take to crack A logarithmic scale from one second to a billion years, with your password's estimated crack time marked. 1 sec1 min1 hr1 day1 year10k yrs1bn yrs —
Estimated time for an offline attacker making 100 billion guesses a second. The scale is logarithmic — each labelled step is roughly a hundredfold jump, which is why adding a few characters matters so much more than adding a symbol.

Length beats complexity

Every character you add multiplies the search space by the size of the character set. Switching symbols on widens it once. That is why a long lowercase-only password beats a short one with every box ticked, and why the advice to bolt punctuation onto a short password was always the weaker half of the guidance.

Entropy in bits for four password styles Style Entropy (higher is better) P@ssw0rd12372 bitsLooks complex. Every substitution is in the first list an attacker tries.Random 8 chars52 bitsShort, even with every character type switched on.Random 16 chars105 bitsThe practical sweet spot for a manager-generated password.4 random words52 bitsDiceware-style. Memorable, and stronger than it looks. Below ~60 bits is crackable by a determined attacker; above ~80 bits is comfortable.
Entropy assumes each choice is genuinely random. "P@ssw0rd123" scores badly not because it lacks symbols but because the substitutions are predictable — cracking tools apply them automatically from a dictionary base.
The substitution trick has been in the attack dictionaries for decades. Replacing a with @ and o with 0 adds almost nothing, because the tools that guess passwords generate those variants from a wordlist for free. What defeats them is randomness they cannot enumerate.

What to do with the password once you have one

A strong password only works if it is unique to one account, which in practice means a password manager — nobody remembers forty of these. Generate directly into the manager, let it fill the site, and never reuse. Credential-stuffing attacks work entirely on passwords reused between a breached site and a valuable one.

Then add two-factor authentication where it is offered. An app-based code or a hardware key protects the account even if the password leaks, and it is a bigger practical upgrade than any amount of extra password length.

Modern guidance from NIST has also dropped two old habits: forced rotation every 90 days, which pushes people toward predictable increments, and composition rules that mandate one of each character type. Length, uniqueness and a check against known-breached passwords do more.

Questions

Are these passwords generated safely?

Yes. They are produced in your browser using the Web Crypto API (crypto.getRandomValues), which is a cryptographically secure random source — not Math.random, which is predictable and unsuitable for secrets. Nothing is transmitted, logged or stored, and the page works with your network disconnected.

How are the crack times calculated?

Entropy is length × log₂(character-set size), and the estimate assumes an offline attacker making 100 billion guesses a second against a fast hash, finding the password halfway through the keyspace on average. Real numbers vary enormously: a site using bcrypt or Argon2 slows that by many orders of magnitude, while a leaked unsalted MD5 database is far faster. Treat the scale as relative, not a promise.

Is a passphrase really as strong as a random password?

Four words drawn randomly from a 7,776-word list gives about 52 bits — comparable to a random eight-character password, and far easier to remember. The catch is the word list: words you chose yourself, or a quote, carry a fraction of that. Randomness has to come from a real random source, not from your own head.

References

  1. NIST SP 800-63B — Digital Identity Guidelines, memorized secrets
  2. MDN — Crypto.getRandomValues()
  3. EFF — Deep dive on passphrases and dice-generated word lists
  4. NCSC — Password policy guidance

Reviewed September 2026.