What makes a password strong
A strong password is one that an attacker cannot guess in any practical amount of time. Two things decide that: how long it is, and how many different characters each position could be. Randomness matters too. A password you invent, such as a pet’s name with a year on the end, is far easier to guess than its length suggests, because people choose in predictable ways.
This tool picks every character at random from the sets you allow. That makes its strength easy to measure, and it means there is no pattern to exploit.
How to use the password generator
- A new password appears in Your password as soon as the page loads.
- Drag the Length slider, or use the minus and plus buttons, to choose from 4 to 128 characters. The default is 20.
- Under Characters to use, turn Uppercase, Lowercase, Numbers and Symbols on or off.
- Choose your options:
- Avoid look-alikes (I l 1 O 0) removes characters that are easy to confuse.
- Use every chosen type makes sure at least one character from each selected set appears.
- Press New for another password, and Copy to copy it.
- Need several? Pick a number in How many passwords. They appear in All passwords, and Copy all copies the whole list.
Below the password, a bar and a label show the strength with an estimate in bits.
Strength labels
| Bits of entropy | Label |
|---|---|
| under 28 | Very weak |
| 28 to 44 | Weak |
| 45 to 63 | Fair |
| 64 to 99 | Strong |
| 100 or more | Very strong |
Examples
These passwords and figures come from running the generator. Do not use them, since they are now public.
| Length | Characters | Bits | Label | Example |
|---|---|---|---|---|
| 6 | Numbers | 19.93 | Very weak | 546382 |
| 8 | Lowercase | 37.60 | Weak | orvapcvl |
| 8 | All four sets | 51.93 | Fair | QpF4b@<V |
| 12 | All four sets | 77.90 | Strong | .y9}g-.ta$rP |
| 16 | Letters and numbers | 95.27 | Strong | ydrGkOZ9PrXPB6TL |
| 16 | All four sets | 103.87 | Very strong | Aj~oJ-WDTW}8rJu2 |
| 20 | All four sets | 129.84 | Very strong | CwEfwEyMg)>w~b-tMx.9 |
| 20 | All four, no look-alikes | 127.50 | Very strong | B;8#]&Dr/*3X8y]fP#-P |
Notice that length does more than variety. Going from 8 to 16 characters with all four sets roughly doubles the bits.
How it works
The four sets hold 26 capitals, 26 small letters, 10 digits and 28 symbols, for 90 characters in total. Avoid look-alikes removes 7 of them: I, l, 1, the pipe, O, 0 and o. That leaves 83.
Each character is drawn with crypto.getRandomValues, the browser’s cryptographic random number source. The tool maps random numbers to characters with rejection sampling instead of a plain remainder, so every character in the pool is exactly as likely as any other.
When Use every chosen type is on, a password that happens to miss one of your chosen sets is thrown away and a new one is drawn. That keeps the result evenly random.
The strength estimate is the length multiplied by log2 of the pool size. For 20 characters from 90, that is 20 x 6.49, about 129.84 bits. This is an upper bound. Requiring every type slightly reduces the number of possible passwords, by a small amount for normal lengths.
Privacy and security
- Nothing leaves your device. There is no server step. The password exists only on the page until you copy it.
- Nothing is saved. Reload the page and the passwords are gone. There is no history on this tool, on purpose.
- Clear your clipboard after pasting on a shared computer.
- Use a password manager. A random password is only useful if you can store it safely. Managers can fill it in for you, so length costs you nothing.
- Turn on two-factor sign-in where you can. A strong password does not help if it is stolen by a fake login page.
The bits shown assume the password was generated randomly, as here. They do not apply to a password you made up and typed into another checker.
Other ways to generate a password
On a computer with Python, this prints a new 20-character password of letters and digits each time:
python -c "import secrets, string; a = string.ascii_letters + string.digits; print(''.join(secrets.choice(a) for _ in range(20)))"
With OpenSSL installed, openssl rand -base64 18 prints 24 random characters. Most password managers also have a built-in generator.
Avoid the RAND function in Excel and Math.random in JavaScript for passwords. They are not designed to be unpredictable.
Related tools
For unique IDs rather than secrets, use the UUID generator. For random numbers in a range, use the random number generator. To make a checksum of a file, use the MD5 hash generator.