Secure Password Generator
Generate cryptographically secure passwords and passphrases with real-time entropy and crack-time estimates. 100% client-side — nothing leaves your browser.
Password generator
Memorable format — ~34 bits of true entropy. Best for low-risk accounts or when paired with two-factor authentication.
Multiple passwords
What Makes a Password Strong?
TL;DR: Password strength comes down to two things — length and true randomness. A 16-character password using all character types reaches approximately 102 bits of entropy, enough to resist modern brute-force attacks for billions of years.
1. Length Is the Biggest Factor
Each additional character multiplies the number of possible passwords by the pool size. Going from 8 to 16 characters (83-character pool) raises entropy from 51 bits to 102 bits — doubling the length doubles the bits, but the actual search space grows exponentially (from 251 to 2102 — a trillion trillion times larger).
2. Cryptographically Secure Randomness
This tool uses window.crypto.getRandomValues(), the browser's
cryptographically secure random number generator (CSPRNG). Unlike Math.random(),
which is predictable, a CSPRNG produces unpredictable output suitable for security applications.
3. Character Pool Size
More character types mean a larger pool, which means more entropy per character.
This tool uses a 21-symbol set (!@#$%^&*()-_=+[]{}<>?),
giving a combined pool of 83 characters when all types are enabled.
Entropy Reference
| Length | Character Types | Pool | Entropy |
|---|---|---|---|
| 8 | Lowercase only | 26 | 37.6 bits |
| 12 | Lowercase only | 26 | 56.4 bits |
| 8 | Alphanumeric | 62 | 47.6 bits |
| 12 | Alphanumeric | 62 | 71.5 bits |
| 16 | Alphanumeric | 62 | 95.3 bits |
| 12 | All types | 83 | 76.5 bits |
| 16 | All types | 83 | 102.0 bits ✓ |
| 20 | All types | 83 | 127.5 bits |
Crack time assumes an offline attack at 10 billion guesses per second (typical for SHA-256 on a GPU). For bcrypt or Argon2id, actual crack rates are orders of magnitude slower.
Security Standards
NIST SP 800-63B (Digital Identity Guidelines) recommends checking passwords against known-breached lists, allowing passphrases of up to 64 characters, and not enforcing periodic rotation or arbitrary complexity rules. For randomly generated passwords, security professionals broadly recommend targeting 80+ bits of entropy for strong protection.
Explore the Guides
Password Entropy Explained
Understand the formula, bits, and how many you actually need.
How Secure Is My Password?
Crack times, attack methods, and real entropy explained.
Password vs. Passphrase
Which is more secure? Compare entropy and memorability.
Strong WiFi Password Examples
WPA2/WPA3 requirements and how to generate a secure router password.
FAQ
What is the most secure way to generate a password?
Use a generator powered by a CSPRNG (like window.crypto.getRandomValues()),
target at least 16 characters across all character types (≈102 bits of entropy),
and store it in a password manager. Never invent passwords yourself.
What is password entropy?
Password entropy measures unpredictability in bits. It is calculated as length × log₂(pool size). A 16-character password from an 83-character pool has 102 bits of entropy.
How many bits of entropy should a password have?
Security professionals recommend at least 80 bits for strong protection. Passwords above 100 bits resist brute-force attacks even with high-speed hardware.
Is this generator safe?
Yes. Passwords are generated entirely in your browser using
window.crypto.getRandomValues(). Nothing is transmitted to any server.
What is the difference between a password and a passphrase?
A password is a short random string; a passphrase uses multiple random words. Read our full comparison: password vs. passphrase.
What does the crack time estimate mean?
It represents the worst-case time to exhaust all possible passwords at 10 billion guesses per second — a typical offline attack rate against SHA-256 hashes on a modern GPU. Online attacks are far slower due to rate-limiting.
Can I use this tool to create a strong WiFi password?
Yes. WPA2 and WPA3 support passwords from 8 to 63 characters. A 16-character random password gives 102 bits of entropy — far beyond any practical attack. See our WiFi password guide.