Random Password Generator

Long, random, impossible-to-guess passwords — created and kept inside your browser.

How to generate a strong password

  1. Drag the length slider. Sixteen characters is a good default; twenty or more for anything important.
  2. Leave the four character sets ticked for the widest pool. Untick symbols only if the site rejects them — every password is guaranteed to contain at least one character from each set you leave ticked.
  3. Press Generate passwords. Five are produced at a time so you can pick one you can type.
  4. Copy the one you want straight into your password manager, and do not paste it anywhere else.

Why random beats memorable

People are drawn to passwords built from words, dates and substitutions — Summer2024! and its relatives. The problem is that those patterns are exactly what a cracking tool tries first. A modern machine working against a fast hash can test billions of candidates a second, and because so many people reach for the same kinds of substitutions, a dictionary with a handful of rules covers an enormous share of real passwords.

Randomness removes the pattern. Each character here is drawn independently from the pool you selected, so knowing every other character tells an attacker nothing about the next one. The trade is that the result is not memorable, which is why the answer is not to memorise it: let a password manager store it, and remember one strong passphrase for the manager instead.

Length matters more than complexity. Adding a character multiplies the search space by the size of the pool, while adding a symbol only enlarges the pool slightly. That is why the entropy figure shown after each generation is the number to watch: a sixteen-character password drawn from 94 possible characters carries roughly 100 bits, and every extra bit doubles the work an attacker has to do. Once you are past about eighty bits, the password is no longer the weak point — the site you gave it to is.

Password generator FAQ

Are the passwords sent anywhere?

No. The generator runs entirely in your browser using crypto.getRandomValues. Nothing is transmitted or stored, and closing the tab erases the result.

How long should a password be?

Sixteen random characters from letters, digits and symbols is roughly 100 bits of entropy — comfortably beyond brute force. Twelve characters, around 70 bits, is still fine for most accounts. Length buys more security than complexity.

What does the entropy figure mean?

It measures how many guesses an attacker would need. Each extra bit doubles the work. Sixty bits is strong against an offline attack, eighty bits is out of reach, and past a hundred bits the password is simply not the weak link any more.

Should I let the browser remember the password?

Generally yes. A password manager or the browser's built-in store lets you use a different long random password on every site, which is far safer than reusing one memorable password everywhere.

Related tools