Password Generator→Specialized Version
🔑

Alphanumeric Password Generator

Generate 20-character random passwords in your browser

StrengthVery strong · 119 bits

At a trillion guesses per second — an offline attack against a fast hash — exhausting this keyspace takes 1.1e+4 trillion years.

  • OZxYqlTlbcreOPRem4N7
  • ZP1A1sA8ubbxEH9Ia9Wt
  • DbXMC2Sfd9bgZGrbRcub
  • R5jjLSlA64xxGXlCBVjE
  • xJclQB37uUJzIKYTlnKg

Generated locally with crypto.getRandomValues and never transmitted. Even so, a password manager that generates in-process is a better habit than any web page, this one included.

20-Character Passwords

Some systems still cannot handle punctuation: legacy terminals, poorly-escaped connection strings, SAP and Oracle installations of a certain age, and any web form that filters characters instead of parameterising its queries.

Twenty alphanumeric characters more than compensates for the missing symbols — length is worth more than alphabet size, and this setting is stronger than a 16-character password with symbols.

The Entropy of This Setting

Drawing 20 characters from an alphabet of 62 — upper case, lower case, digits, with no symbols — gives about 119 bits of entropy. At a trillion guesses a second, which is what a well-funded attacker with GPUs achieves against a fast hash, exhausting half that space takes 1.1 × 10^16 years.

LengthEntropyTime to crack at 10¹² guesses/sec
8 characters48 bits2 minutes
12 characters71 bits37 years
16 characters95 bits6.3 × 10^8 years
20 characters119 bits1.1 × 10^16 years
24 characters143 bits1.8 × 10^23 years
32 characters191 bits5.0 × 10^37 years
Note how the numbers move: each additional character multiplies the search space by 62, so length buys far more security than complexity rules ever did.

Why Omit Symbols

Alphanumeric-only passwords exist because some systems still break on punctuation: legacy terminals, some database connection strings, and a surprising number of enterprise portals that filter characters they consider dangerous rather than escaping them properly.

The cost is about 0.6 bits per character. Add two or three characters of length and you are ahead of where you started.

Generated in Your Browser

The generator uses crypto.getRandomValues(), the platform's cryptographically secure random source, not Math.random() — which is fast, predictable and unfit for this purpose. Nothing is transmitted and nothing is logged; the value exists only in your tab.

What to Pair It With

At this length brute force stops being the threat, so the remaining improvements are structural:

  • A password manager, which makes a unique password per site free rather than a chore.
Uniqueness matters more than length once you are past 12 characters.
  • Two-factor authentication. An app-based or hardware second factor defeats a stolen
password outright; SMS is weaker than either and far better than nothing.
  • Passkeys where offered. They remove the shared secret entirely, so a phishing site has
nothing to capture.

A 16-character password reused across five sites is weaker in practice than five distinct 12-character ones.

Where Passwords Actually Leak

CauseShare of breachesMitigation
Reuse after another site's breachLargest single causeA unique password per site
PhishingLargeA password manager (it will not autofill on the wrong domain)
Weak or guessableModerateLength and real randomness
Server-side breachModerateNot yours to control; 2FA limits the damage
Notice that three of the four are unaffected by how complex an individual password is. Reuse is the dominant risk, and the only fix is a manager.

Storing Them, If You Are the Server

``javascript // Argon2id is the current recommendation const hash = await argon2.hash(password, { type: argon2.argon2id, memoryCost: 19456, // 19 MiB timeCost: 2, parallelism: 1, }); `

Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per password and generated by the library. Peppering — a secret added outside the database — helps only if the pepper lives somewhere the database dump does not.

Rules Worth Dropping

NIST SP 800-63B now advises against several long-standing practices:

  • Forced periodic rotation. It produces Password1, Password2` and nothing else.
  • Composition rules. They shrink the search space by making the pattern predictable.
  • Password hints and security questions. Both are usually easier to guess than the
password.
  • Truncating length. Accept at least 64 characters; a passphrase should fit.
Check candidates against a breached-password list instead. That single control removes more risk than every composition rule combined.

Frequently Asked Questions

Is a 20-character password enough?

At 119 bits of entropy, brute force is not the threat — an attacker at a trillion guesses a second would need 1.1 × 10^16 years. What actually compromises accounts is reuse across sites, phishing and malware, none of which more length prevents.

Is this generator safe to use?

The password is generated locally with `crypto.getRandomValues()`, the browser’s cryptographically secure random source. Nothing is sent over the network and nothing is stored — closing the tab destroys it. You can verify this by disconnecting from the internet and generating another.

Should I change my passwords regularly?

No. NIST withdrew that advice: forced rotation pushes people toward predictable variations like Summer2025! then Summer2026!. Change a password when there is a reason to — a breach notification, a shared device, a suspicion — and otherwise leave a strong unique password alone.

Related Tools

Explore other tools you might find useful:

More Password Generator tools

You might also need