Password Generator→Specialized Version
🔑

WiFi Password Generator

Generate 20-character random passwords in your browser

StrengthVery strong · 119 bits

At a trillion guesses per second — an offline attack against a fast hash — exhausting this keyspace takes 1.1e+4 trillion years.

  • VjV4rSF5sEETctFKkby6
  • 13wwzBlczmC3pW4IUN6S
  • TbTSIXpnz0mRmYLPZA70

Generated locally with crypto.getRandomValues and never transmitted. Even so, a password manager that generates in-process is a better habit than any web page, this one included.

WiFi Password Generator

A WiFi passphrase is unusual among credentials: typed once per device, then remembered forever — and typed on a television remote, a printer keypad or a smart plug's setup screen. That shapes every decision about it.

Why Length, Not Symbols

WPA2 accepts 8 to 63 characters. The attack is offline: capture the four-way handshake once, then guess at the speed of the attacker's hardware with no network involved and no lockout.

PassphraseResistance
A dictionary wordSeconds
8 random charactersHours to days
12 random charactersYears
20 random alphanumericNot feasible
Symbols add little here and cost a lot: several smart-home devices handle punctuation badly, and reading a tilde aloud to a guest is worse than reading four more letters.

WPA3 Fixes the Offline Attack

WPA3's SAE handshake makes offline dictionary attacks against the captured handshake infeasible, which is the single biggest security improvement in home networking in a decade. Enable WPA3 where every device supports it, and WPA2/WPA3 mixed mode otherwise.

WPS should be off regardless. Its PIN is brute-forceable in hours and bypasses the passphrase entirely.

Give Guests Their Own Network

A guest network isolates visitors from your printers, network storage, cameras and smart-home hub. Rotating its password costs nothing because nothing important is joined to it — whereas changing the main passphrase means re-entering it on every device in the house.

That asymmetry is the whole argument for the guest network: it makes rotation cheap where it is needed and unnecessary where it is expensive.

Also Change the Admin Password

The router's administration password is a separate credential and is very often still the default printed on the label. An attacker on your network who reaches the admin panel can change DNS servers and intercept everything, without ever needing the WiFi passphrase again.

Hiding the SSID Achieves Nothing

A hidden network still broadcasts its name whenever a client looks for it, so it is trivially discoverable — and it makes your devices announce the network name everywhere they go.

Where Passwords Actually Leak

CauseShare of breachesMitigation
Reuse after another site's breachLargest single causeA unique password per site
PhishingLargeA password manager (it will not autofill on the wrong domain)
Weak or guessableModerateLength and real randomness
Server-side breachModerateNot yours to control; 2FA limits the damage
Notice that three of the four are unaffected by how complex an individual password is. Reuse is the dominant risk, and the only fix is a manager.

Storing Them, If You Are the Server

``javascript // Argon2id is the current recommendation const hash = await argon2.hash(password, { type: argon2.argon2id, memoryCost: 19456, // 19 MiB timeCost: 2, parallelism: 1, }); `

Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per password and generated by the library. Peppering — a secret added outside the database — helps only if the pepper lives somewhere the database dump does not.

Rules Worth Dropping

NIST SP 800-63B now advises against several long-standing practices:

  • Forced periodic rotation. It produces Password1, Password2` and nothing else.
  • Composition rules. They shrink the search space by making the pattern predictable.
  • Password hints and security questions. Both are usually easier to guess than the
password.
  • Truncating length. Accept at least 64 characters; a passphrase should fit.
Check candidates against a breached-password list instead. That single control removes more risk than every composition rule combined.

Frequently Asked Questions

Is a 20-character password enough?

At 119 bits of entropy, brute force is not the threat — an attacker at a trillion guesses a second would need 1.1 × 10^16 years. What actually compromises accounts is reuse across sites, phishing and malware, none of which more length prevents.

Is this generator safe to use?

The password is generated locally with `crypto.getRandomValues()`, the browser’s cryptographically secure random source. Nothing is sent over the network and nothing is stored — closing the tab destroys it. You can verify this by disconnecting from the internet and generating another.

Should I change my passwords regularly?

No. NIST withdrew that advice: forced rotation pushes people toward predictable variations like Summer2025! then Summer2026!. Change a password when there is a reason to — a breach notification, a shared device, a suspicion — and otherwise leave a strong unique password alone.

Related Tools

Explore other tools you might find useful:

More Password Generator tools

You might also need