What Is a Random Password?
TL;DR: A random password is one where every character is chosen uniformly at random from a defined pool, using a cryptographically secure random number generator (CSPRNG). This guarantees maximum entropy for the chosen length — making it far stronger than any password a human invents.
This generator uses window.crypto.getRandomValues() with rejection sampling
to eliminate modulo bias, so every character is genuinely unpredictable. It is the same
primitive browsers use for cryptographic keys.
Why Random Beats Human-Invented
Humans are terrible sources of randomness. We reuse passwords, follow keyboard patterns, substitute predictable characters (a→@, o→0), and choose dates and names. Attackers exploit this with dictionaries containing billions of known passwords. A truly random password sidesteps all of it.
Choosing a Length
| Length | Entropy (all types) | Offline crack time | Use case |
|---|---|---|---|
| 8 | 51 bits | Minutes | Too short — avoid |
| 12 | 76.5 bits | Years | Minimum for low-value |
| 16 | 102 bits | Billions of years | Recommended for all accounts |
| 20 | 127.5 bits | Effectively never | High-value accounts |
| 32 | 204 bits | Never | Overkill / archive keys |
FAQ
What is a random password generator?
A tool that creates passwords using a CSPRNG (window.crypto.getRandomValues),
choosing each character uniformly at random to maximize entropy. This one runs entirely in your browser.
Is a random password stronger than one I make up?
Yes. A random 16-character password has ~102 bits of entropy; a human-invented "complex" password often has fewer than 40 bits because it follows a recognizable pattern.
How long should a random password be?
At least 16 characters with all character types (≈102 bits). 12 is the absolute minimum; 20+ is ideal for high-value accounts.
Are these passwords truly random?
Yes — they use the Web Crypto API with rejection sampling to remove modulo bias.
It is not Math.random(), which is unsuitable for security.
Is this generator safe and private?
Yes. All generation happens in your browser. Nothing is sent, logged, or stored, and there is no tracking or analytics.
Related guides: Password Entropy Explained · How Secure Is My Password?
We do not collect, store, or transmit any passwords.