Password Generator

Generate a strong password — see the entropy

Cryptographically random passwords, generated in your browser. See the entropy in bits and the time-to-crack at 1B guesses/sec. Switch to passphrase mode for memorable options. 100% client-side — your password never leaves this page.

click Generate
Entropy
0 bits
Strength
—
Time to crack @ 1B/s
—

Password entropy and time-to-crack: the math every developer should know

A password is a secret string. An attacker who has obtained the password's hash (via database breach, leaked logs, or a side-channel) will try to recover the original string by guessing. The strength of a password is how many guesses they need on average — which is half of the total number of possible passwords the secret could be. We measure this in bits: a password with N bits of entropy is one of 2^N equally-likely possibilities, and a brute-force attacker needs ~2^(N-1) guesses on average to find the right one.

The math, fast

For a password of L characters chosen uniformly from an alphabet of size A, the entropy is:

entropy_bits = L * log2(A)

Common alphabets and their log2 sizes:

A 16-character password using the full 95-character alphabet has 16 * 6.57 ≈ 105 bits of entropy. An attacker brute-forcing at 1 billion guesses/second would need ~2^104 / 10^9 ≈ 2 * 10^22 seconds ≈ 600 billion years. Older than the sun.

Length beats complexity

A common mistake is to add complexity (special characters, mixed case) at the cost of length. The math is against the length, not the symbol soup:

The 16-character lowercase password is stronger than the 8-character mixed one, and easier to type. For passwords managed in a tool, length wins. For passwords you have to type, passphrases win (next section).

Passphrases: memorable entropy

The passphrase tab uses a 7000-word English list. Each word contributes log2(7000) ≈ 12.8 bits. Four words: 51 bits. Five words: 64 bits. Six words: 77 bits. Six random English words are easier to remember than 16 random characters, and at 77 bits they're stronger than most human-chosen 16-character passwords.

This is the diceware principle: pick a short, memorable list of words (7000 in our case, 7776 in canonical diceware), pick N words at random, join them. The result is high-entropy and memorable.

Why "this site" doesn't matter — but "all sites" does

Your bank password, your email password, your social media password, your Netflix password. The math for each one is identical — an attacker with the hash can brute-force any single password at the same speed. The asymmetric danger is when those passwords are the SAME: one site gets breached, the attacker tries the email/password combo on a hundred sites. Most modern attackers do exactly this with credential-stuffing tools.

The right pattern: one unique random password per site, stored in a password manager (1Password, Bitwarden, KeePass). The password manager is the only place you have to remember a strong password — the master password — and that one needs to be the strongest of all.

What NIST actually recommends

NIST SP 800-63B is the US federal password guideline. The 2024 revision says:

Two-factor authentication is the second layer

A strong password protects you when a site's database is breached. A strong password + 2FA (TOTP, WebAuthn) protects you when your password itself is leaked (phishing, keylogger, shoulder-surfing, or your password manager is compromised). Both matter. The right pattern: unique strong passwords in a manager + 2FA on every site that supports it. Most modern sites support TOTP (authenticator apps) and many now support WebAuthn (hardware keys, Touch ID, Face ID, Windows Hello).

Why this generator is 100% client-side

A password generator that sends your password to a server is a logger, not a generator. The server sees every password you generate, which means the server is a single point of failure for every password you've ever used. The page you're reading now: zero HTTP calls per roll. The HTML and JavaScript load once when you open the page; the password is generated locally via crypto.getRandomValues; you copy it; you paste it into your password manager. No network round trips for the password itself.

Verify by opening DevTools (F12), clicking the Network tab, then clicking Generate. You'll see no requests fire after the initial page load. That's the difference between a generator and a logger.

Related SiteTrace tools: Random Color, Word Counter, Security Headers Checker.