How to use
Pick a mode. Random password is a string of characters of the chosen length (16 by default), ideal for a password manager. Passphrase is several random dictionary words (the diceware method): easy to remember and type, good for a master password or computer login. PIN is digits only, for cards and phones.
Passwords are generated right in your browser with the cryptographic generator crypto.getRandomValues, without modulo bias. Nothing is sent to a server or stored. Passwords refresh whenever you change a setting; the Generate button gives a new batch.
Entropy is computed from the generator settings: log2(alphabetlength) for a random password, words × log2(list size) for a passphrase. Crack time is the average (half of the key space): offline means a leaked hash attacked with GPUs, online means guessing through a login form.
Password security
- Length beats complexity. Every extra character multiplies the number of possibilities. "Password1!" looks complex but is in every dictionary; 16 random characters or 5–6 random words are far stronger. NIST SP 800-63B agrees: drop composition rules like "must contain a symbol", require length and check against breach lists.
- A unique password for every site. Sites get breached all the time, and stolen email + password pairs are immediately tried on other services.
- Use a password manager (Bitwarden, KeePassXC, 1Password, or the one built into your browser or OS). Then you only remember one master password; make it a passphrase of 6+ words.
- Turn on two-factor authentication. Best are passkeys or a hardware key, then an authenticator app. SMS is the weakest option: numbers can be hijacked by SIM swapping.
- Don’t rotate passwords without a reason. Forced changes every 90 days only lead to Password2, Password3. Change it right away if the service was breached or you suspect a leak.
- Check for leaks at haveibeenpwned.com. Its password check uses k-anonymity: only the first 5 characters of the hash are sent, never the password itself.
- Beware of phishing. The longest password won’t help if you type it into a fake site. Check the address; password managers and passkeys won’t fill in credentials on the wrong domain.
- Security questions are weak. Your mother’s maiden name or pet’s name are easy to find. If a question is mandatory, answer with a random string and keep it in your manager.
- Why passphrases are easier to remember. Five words are easier to hold in memory than 16 random symbols, with comparable strength: each word from a 1296-word list adds ~10.3 bits, from a 7776-word list ~12.9 bits. The key is that the generator picks the words, not you: a made-up phrase or a song lyric is easy to guess.
Examples (average offline crack time at 1010 guesses/s):
| Password | Entropy | Crack time |
|---|---|---|
| "Password1!", a word with substitutions | — | instant (it is in dictionaries) |
| 6-digit PIN | 20 bits | instant (fine online with attempt limits) |
| 8 lowercase letters | 38 bits | ~10 seconds |
| 4 words (EFF, 1296) | 41 bits | ~2 minutes |
| 8 chars from all 94 | 52 bits | ~4 days |
| 6 words (EFF, 1296) | 62 bits | ~7 years |
| 12 chars A–Z, a–z, 0–9 | 71 bits | ~5 thousand years |
| 8 words (EFF, 1296) | 83 bits | ~12 million years |
| 16 chars with symbols | ~104 bits | practically never |