20-Character Passwords
Some systems still cannot handle punctuation: legacy terminals, poorly-escaped connection strings, SAP and Oracle installations of a certain age, and any web form that filters characters instead of parameterising its queries.
Twenty alphanumeric characters more than compensates for the missing symbols — length is worth more than alphabet size, and this setting is stronger than a 16-character password with symbols.
The Entropy of This Setting
Drawing 20 characters from an alphabet of 62 — upper case, lower case, digits, with no symbols — gives about 119 bits of entropy. At a trillion guesses a second, which is what a well-funded attacker with GPUs achieves against a fast hash, exhausting half that space takes 1.1 × 10^16 years.
| Length | Entropy | Time to crack at 10¹² guesses/sec |
|---|---|---|
| 8 characters | 48 bits | 2 minutes |
| 12 characters | 71 bits | 37 years |
| 16 characters | 95 bits | 6.3 × 10^8 years |
| 20 characters | 119 bits | 1.1 × 10^16 years |
| 24 characters | 143 bits | 1.8 × 10^23 years |
| 32 characters | 191 bits | 5.0 × 10^37 years |
Why Omit Symbols
Alphanumeric-only passwords exist because some systems still break on punctuation: legacy terminals, some database connection strings, and a surprising number of enterprise portals that filter characters they consider dangerous rather than escaping them properly.
The cost is about 0.6 bits per character. Add two or three characters of length and you are ahead of where you started.
Generated in Your Browser
The generator uses crypto.getRandomValues(), the platform's cryptographically secure
random source, not Math.random() — which is fast, predictable and unfit for this purpose.
Nothing is transmitted and nothing is logged; the value exists only in your tab.
What to Pair It With
At this length brute force stops being the threat, so the remaining improvements are structural:
- A password manager, which makes a unique password per site free rather than a chore.
- Two-factor authentication. An app-based or hardware second factor defeats a stolen
- Passkeys where offered. They remove the shared secret entirely, so a phishing site has
A 16-character password reused across five sites is weaker in practice than five distinct 12-character ones.
Where Passwords Actually Leak
| Cause | Share of breaches | Mitigation |
|---|---|---|
| Reuse after another site's breach | Largest single cause | A unique password per site |
| Phishing | Large | A password manager (it will not autofill on the wrong domain) |
| Weak or guessable | Moderate | Length and real randomness |
| Server-side breach | Moderate | Not yours to control; 2FA limits the damage |
Storing Them, If You Are the Server
``javascript
// Argon2id is the current recommendation
const hash = await argon2.hash(password, {
type: argon2.argon2id,
memoryCost: 19456, // 19 MiB
timeCost: 2,
parallelism: 1,
});
`
Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per
password and generated by the library. Peppering — a secret added outside the database —
helps only if the pepper lives somewhere the database dump does not.
Rules Worth Dropping
NIST SP 800-63B now advises against several long-standing practices:
Forced periodic rotation. It producesPassword1,Password2` and nothing else.- Composition rules. They shrink the search space by making the pattern predictable.
- Password hints and security questions. Both are usually easier to guess than the
- Truncating length. Accept at least 64 characters; a passphrase should fit.