Password Generatorโ†’Specialized Version
๐Ÿ”‘

Strong Password Generator

Generate strong random passwords

StrengthVery strong ยท 129 bits

At a trillion guesses per second โ€” an offline attack against a fast hash โ€” exhausting this keyspace takes 9.8e+6 trillion years.

  • .,W;{U!,$,TEqq=S>>d[
  • @u(,**S_hx}C1-rZh0th
  • ,NF6t5o{5%rCj&IZTZ)K
  • @[5=,+%1a.]iM]nLc1WK
  • fP_Se>qrP%[q9Mdet#UE

Generated locally with crypto.getRandomValues and never transmitted. Even so, a password manager that generates in-process is a better habit than any web page, this one included.

What Makes a Password Strong

Not symbols. Not a capital letter at the front and a "1!" at the end. Strength is entropy: how many guesses an attacker needs on average, which depends on how the password was generated rather than how complicated it looks.

`` entropy = length ร— logโ‚‚(pool size) `

PasswordLooksReal entropy
P@ssw0rd!Complex~14 bits โ€” in every cracking list
Summer2024!Complex~20 bits โ€” season + year is the top pattern
x7Kq2mWvR9pLz4TnRandom95 bits
20 chars, all setsRandom130 bits

Length Beats Complexity

Each extra character multiplies the search space by the pool size. Each extra character *class* only widens the pool once.

Change to an 8-char lowercase passwordNew entropy
Baseline (8 lowercase)38 bits
Add uppercase46 bits
Add digits and symbols52 bits
Instead, make it 16 lowercase75 bits
Doubling the length beats adding every character class you have.

Crack Times

At 10ยนยฒ guesses per second โ€” an offline attack on a fast hash with rented GPUs:

EntropyTime to exhaust
40 bits9 minutes
60 bits18 days
80 bits38,000 years
100 bits40 billion years
Against a password stored properly with bcrypt or Argon2, divide the guess rate by about a billion โ€” which is the entire point of using a slow hash.

Rules Worth Following

  • One password per account. Reuse is what turns one breach into ten.
  • 20 characters where you can. Anywhere a manager types it for you, length is free.
  • Never reuse across work and personal. The blast radius is what matters.
  • Turn on 2FA. It is the only control that survives a password leak.

Where Passwords Actually Leak

CauseShare of breachesMitigation
Reuse after another site's breachLargest single causeA unique password per site
PhishingLargeA password manager (it will not autofill on the wrong domain)
Weak or guessableModerateLength and real randomness
Server-side breachModerateNot yours to control; 2FA limits the damage
Notice that three of the four are unaffected by how complex an individual password is. Reuse is the dominant risk, and the only fix is a manager.

Storing Them, If You Are the Server

`javascript // Argon2id is the current recommendation const hash = await argon2.hash(password, { type: argon2.argon2id, memoryCost: 19456, // 19 MiB timeCost: 2, parallelism: 1, }); `

Never store plaintext, never store a fast hash, never encrypt reversibly. Salt is per password and generated by the library. Peppering โ€” a secret added outside the database โ€” helps only if the pepper lives somewhere the database dump does not.

Rules Worth Dropping

NIST SP 800-63B now advises against several long-standing practices:

  • Forced periodic rotation. It produces Password1, Password2` and nothing else.
  • Composition rules. They shrink the search space by making the pattern predictable.
  • Password hints and security questions. Both are usually easier to guess than the
password.
  • Truncating length. Accept at least 64 characters; a passphrase should fit.
Check candidates against a breached-password list instead. That single control removes more risk than every composition rule combined.

Frequently Asked Questions

How long should a strong password be?

At least 16 characters where a password manager types it for you, and 20 or more for anything high-value. Below 12 characters, a random password is within reach of a determined offline attack.

Do I still need symbols?

They help, but far less than length. Going from 16 to 20 characters adds about 26 bits of entropy; adding symbols to a 16-character password adds about 8.

Is generating a password in a browser safe?

Generation here uses crypto.getRandomValues and happens entirely in your tab โ€” you can verify no request is made. A password manager is still the better habit, because it never renders the secret in a page at all.

Related Tools

Explore other tools you might find useful:

More Password Generator tools

You might also need