Strong Password Generator
Generate cryptographically secure random passwords in your browser.
Why use a password generator?
Humans are bad at creating random passwords. We reuse patterns, include personal information, and choose predictability. A good password generator uses cryptographic randomness to create passwords that are mathematically hard to guess.
Password best practices
- Use a unique password for every account
- 16+ characters minimum for important accounts
- Use a password manager to store them
- Enable two-factor authentication (2FA) everywhere
- Never reuse passwords across sites
- Change passwords immediately if a site is breached
What makes a password strong?
- Length: Most important. 16+ characters
- Randomness: No patterns, dictionary words, or personal info
- Character variety: Mix uppercase, lowercase, numbers, symbols
- Uniqueness: Different for every account
Privacy
Passwords are generated entirely in your browser using the Web Crypto API. Nothing is uploaded, logged, or stored.
Frequently Asked Questions
Are these passwords secure?
Yes. Passwords are generated using crypto.getRandomValues(), which is cryptographically secure. They are generated locally in your browser and never sent over the network.
How long should my password be?
For most accounts: 16+ characters. For high-security accounts (banking, email): 20+ characters. Length matters more than complexity.
What does 'entropy' mean?
Entropy is measured in bits and represents how unpredictable a password is. 80+ bits is considered strong against modern attacks. 128+ bits is extremely strong.
What are 'ambiguous' characters?
Characters that look similar: I, l, 1, O, 0, o. Excluding them makes passwords easier to type manually without mistakes.
Should I use symbols?
Yes, if the site allows them. Symbols increase entropy per character. But length is still the most important factor.
Is this free?
Yes. Everything runs in your browser.