WiFi Password Generator
A WiFi passphrase is unusual among credentials: typed once per device, then remembered forever — and typed on a television remote, a printer keypad or a smart plug's setup screen. That shapes every decision about it.
Why Length, Not Symbols
WPA2 accepts 8 to 63 characters. The attack is offline: capture the four-way handshake once, then guess at the speed of the attacker's hardware with no network involved and no lockout.
| Passphrase | Resistance |
|---|---|
| A dictionary word | Seconds |
| 8 random characters | Hours to days |
| 12 random characters | Years |
| 20 random alphanumeric | Not feasible |
WPA3 Fixes the Offline Attack
WPA3's SAE handshake makes offline dictionary attacks against the captured handshake infeasible, which is the single biggest security improvement in home networking in a decade. Enable WPA3 where every device supports it, and WPA2/WPA3 mixed mode otherwise.
WPS should be off regardless. Its PIN is brute-forceable in hours and bypasses the passphrase entirely.
Give Guests Their Own Network
A guest network isolates visitors from your printers, network storage, cameras and smart-home hub. Rotating its password costs nothing because nothing important is joined to it — whereas changing the main passphrase means re-entering it on every device in the house.
That asymmetry is the whole argument for the guest network: it makes rotation cheap where it is needed and unnecessary where it is expensive.
Also Change the Admin Password
The router's administration password is a separate credential and is very often still the default printed on the label. An attacker on your network who reaches the admin panel can change DNS servers and intercept everything, without ever needing the WiFi passphrase again.
Hiding the SSID Achieves Nothing
A hidden network still broadcasts its name whenever a client looks for it, so it is trivially discoverable — and it makes your devices announce the network name everywhere they go.
Where Passwords Actually Leak
| Cause | Share of breaches | Mitigation |
|---|---|---|
| Reuse after another site's breach | Largest single cause | A unique password per site |
| Phishing | Large | A password manager (it will not autofill on the wrong domain) |
| Weak or guessable | Moderate | Length and real randomness |
| Server-side breach | Moderate | Not yours to control; 2FA limits the damage |
Storing Them, If You Are the Server
``javascript
// Argon2id is the current recommendation
const hash = await argon2.hash(password, {
type: argon2.argon2id,
memoryCost: 19456, // 19 MiB
timeCost: 2,
parallelism: 1,
});
`
Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per
password and generated by the library. Peppering — a secret added outside the database —
helps only if the pepper lives somewhere the database dump does not.
Rules Worth Dropping
NIST SP 800-63B now advises against several long-standing practices:
Forced periodic rotation. It producesPassword1,Password2` and nothing else.- Composition rules. They shrink the search space by making the pattern predictable.
- Password hints and security questions. Both are usually easier to guess than the
- Truncating length. Accept at least 64 characters; a passphrase should fit.