How to use
- Set the length with the slider, from 4 to 128 characters. Pick how many passwords you want, from 1 to 10.
- Choose the kinds of characters: lower case, upper case, digits and symbols. Tick the look-alike option to leave out l, 1, I, O and 0.
- Press Generate for new passwords, or Copy all to copy them. The strength label and the entropy estimate appear below.
Examples
Length 16, all four kinds of characters
→ 86 possible characters, about 102.8 bits of entropy: very strongThe pool is 26 lower case, 26 upper case, 10 digits and 24 symbols.
Length 12, lower case and digits only
→ 36 possible characters, about 62 bits of entropy: fairFewer kinds of characters and a shorter length give much less entropy.
Length 3
→ Error: the length must be from 4 to 128
How it works
Each character is chosen with crypto.getRandomValues. To pick a number from 0 up to a limit without bias, the tool throws away random values at the top of the range that would favour some results, which is called rejection sampling.
For each kind of character you selected, one character of that kind is drawn first, so the password always includes every selected kind. The remaining positions are filled from all selected characters together, and the whole list is then shuffled with the same secure source.
The entropy estimate assumes every character was chosen independently and uniformly from the pool. The page never receives the passwords, and reloading it discards them.
Sources
- NIST SP 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Management
- MDN: Crypto.getRandomValues()
Frequently asked questions
- Are these passwords really random?
- They come from your browser's cryptographically secure random number generator (crypto.getRandomValues), not from Math.random. Values that would make some characters more likely than others are thrown away, so every character in the pool is equally likely.
- Are my passwords stored or sent anywhere?
- No. They are made on your device and only exist on this page until you reload it. Nothing is sent to a server and nothing is saved.
- How long should a password be?
- Length matters most. For important accounts, 16 or more random characters is a common choice, and a password manager means you never have to remember them. NIST's guidance on passwords also recommends favouring length over rules that force certain kinds of characters.
- What does the entropy figure mean?
- It is length times the base-2 logarithm of the number of possible characters, which measures how hard a password would be to guess if an attacker knows how it was made. It is valid only for passwords picked at random like these, not for passwords a person invented. The labels Weak, Fair, Strong and Very strong are this tool's own rough bands: under 50, 50 to 70, 70 to 100 and over 100 bits.
- Why leave out look-alike characters?
- Characters such as l, 1, I, O and 0 are easy to confuse when you read a password aloud or type it by hand. Leaving them out slightly reduces the pool, so add a few characters of length to make up for it.