Password generator
Strong random passwords, generated on your device by the browser cryptographic generator and never sent anywhere. Pick the length and the character sets, and see the real entropy in bits rather than a colour coded guess. Free and no signup.
Entropy
129.5 bits
Very strong. Overkill for most accounts, which is the right kind of overkill.
20 characters drawn from a pool of 89, so 20 × log2(89) = 129.5 bits. An attacker who has stolen the password database and can try 1e+12 guesses per second against a fast hash needs 1.5e+19 years on average. That guessing rate is an assumption, not a measurement, and a slow hash such as bcrypt or Argon2 makes it far worse for the attacker.
Requiring one character from each set removes a few possible passwords from the pool, so the true figure is a fraction of a bit under the number above.
Runs in your browser. The password is produced by crypto.getRandomValues in this tab. It is never sent over the network, never logged and never stored, so closing the page is all it takes to destroy it.
Where the randomness comes from
Every character is drawn with crypto.getRandomValues, the browser cryptographically secure generator, seeded by the operating system. The other obvious candidate, Math.random, is a fast statistical generator with a predictable internal state, and an attacker who sees a few of its outputs can reconstruct the rest. It has no business generating a secret, and it appears nowhere in this tool.
Picking a character also has to be done carefully. Taking the remainder of a raw random number by the pool size makes the first few characters of the pool very slightly more likely than the rest, because the number range does not divide evenly. This generator rejects and redraws the values that fall in that uneven tail, so every character is equally likely.
What entropy in bits means
A password chosen at random from a pool of P characters, L characters long, could have come out PL different ways, all equally likely. Entropy states that number as a power of two, which is a more workable size.
Sixteen characters from the 62 character letters and digits pool is 16 × log2(62) = 95.3 bits. Add the symbol set for a pool of 89 and the same length gives 103.6 bits. Drop to 8 characters from a pool of 64 and the number is exactly 48 bits, which is small enough to fall in an afternoon.
This is a property of how the password was generated, not of the string it produced. A password manager entry and a memorable phrase can print the same characters and have wildly different entropy, because what matters is how many other passwords were equally likely to appear.
Why the coloured strength meters mislead
Most strength meters score the string in front of them: one point for a capital, one for a digit, one for a symbol. Password1! collects all three and still falls almost immediately, because it is a dictionary word with the exact decorations every cracking tool tries first.
Length is the cheapest real improvement. Every extra character multiplies the search space by the pool size, so going from 12 to 16 characters is worth far more than adding one exclamation mark to the end of a short password.
A practical target is 80 bits or more for anything you would mind losing, which is around 13 characters of letters and digits. Above 100 bits the password is no longer the weak part of your security, and your attention is better spent on turning on two factor authentication and never reusing the password anywhere else.
Frequently asked questions
- Is the password generated on my device or on a server?
- On your device. The page calls crypto.getRandomValues in your browser, so the password exists only in this tab and is never sent anywhere. You can turn off your network connection and keep generating.
- What makes this random enough for a password?
- It uses the browser cryptographic generator rather than Math.random. Math.random is a fast statistical generator with a predictable internal state, which is fine for animations and unsuitable for secrets. Each character is also drawn with rejection sampling, so no character is slightly more likely than another.
- What does the entropy in bits actually mean?
- It is the size of the space the password was drawn from, expressed as a power of two. A password of L characters from a pool of P characters has L multiplied by the base two logarithm of P bits, because there are P to the power L equally likely results. Sixteen characters from the 62 letter and digit pool is 95.3 bits.
- Why show bits instead of a strength score out of five?
- Because the bits are a calculation and the score is a guess. Coloured meters usually reward a capital letter and a trailing exclamation mark, which is why Password1! scores well and falls in seconds. Entropy measures how the password was generated, which is the thing that decides how long guessing takes.
- How long should my password be?
- Long enough to clear roughly 80 bits for anything that matters, which is 13 characters from the letters and digits pool or 12 with symbols added. Length buys more than character variety does, so going from 12 to 16 characters helps more than adding one punctuation mark.
- Should I exclude ambiguous characters?
- Only when a human has to read the password back, from a printed sheet or over the phone, since it removes the pairs that look alike in most fonts. It shrinks the pool and therefore the entropy, and the figure on the page updates to show exactly how much, so add a character or two of length to compensate.
Good at remembering passwords. Better at remembering your course.
FORKSAI turns your notes, slides and PDFs into flashcards and spaced repetition sessions, so the material you are studying stays in your head.
The tool above stays free and needs no account.
More free tools
There are file and format tools too, such as image converter, compress image to size, favicon generator, and the full set is on the free tools hub.
Plan your next review session
Use the free student study kit to plan a week of revision, check flashcard quality, and record mistakes from practice questions.
Need a deck first? Turn a lecture PDF into editable flashcards, then follow the active recall guide to practise answering before revealing the back of each card.
Working toward an exam? Build a daily target with the exam study planner, protect the session with the Pomodoro study timer, or check your current result with the weighted GPA calculator.