TechWeirdoTools

Settings

20 characters
Characters

Your password

Click regenerate as often as you like — nothing is saved.

Strength: — Entropy: — Offline crack time: —

Need several?

Generate a batch with the same settings.

How to create a strong password

  1. Choose password or passphrase

    Random passwords pack the most strength into the fewest characters. Passphrases are longer but far easier to type and remember — great for a master password.

  2. Adjust length and characters

    Longer is stronger. 16+ characters with all four character types, or 5+ random words, comfortably exceeds 64 bits of entropy.

  3. Copy it into your password manager

    Use a unique password for every account and let a password manager remember them. Reuse is the most common way accounts get taken over.

How password strength is measured

Strength is measured in bits of entropy: the base-2 logarithm of how many equally likely passwords the generator could have produced. Each extra bit doubles an attacker’s work. A 20-character password from all 94 printable ASCII characters has about 131 bits — far beyond any brute-force attack.

EntropyRatingExample
< 40 bitsVery weak8 lowercase letters
40–59 bitsWeak10 letters and digits
60–79 bitsReasonable12 mixed characters, or 5 random words
80–99 bitsStrong14+ mixed characters, or 7 random words
100+ bitsVery strong16+ mixed characters, or 8+ random words

The crack-time estimate assumes an offline attacker trying 100 billion guesses per second against a fast hash — a pessimistic, worst-case scenario. Sites that store passwords with bcrypt or Argon2 slow attackers down by many orders of magnitude.

Why this generator is safe to use

Characters and words are chosen with crypto.getRandomValues() using rejection sampling, so every option is exactly equally likely. Generation happens entirely in your browser; nothing is transmitted, logged or stored.

Frequently asked questions

Is this password generator safe?

Yes. Passwords are generated locally with the Web Crypto API and never leave your device. The page makes no network request with your password, and nothing is saved.

How long should my password be?

Use at least 16 random characters for important accounts, or a passphrase of 5–6 random words. NIST guidance favours length over forced complexity rules.

Are passphrases as secure as random passwords?

They can be. Each word from a 7,776-word list adds about 12.9 bits, so six random words (≈77 bits) are about as strong as a 12-character random password — and much easier to type on a phone.

Why avoid look-alike characters?

Characters like l, 1, I, O and 0 are easy to confuse when reading a password aloud or typing it from another screen. Excluding them costs a little entropy, which you can recover by adding a character or two.

Where do the passphrase words come from?

From the Electronic Frontier Foundation’s large diceware wordlist, designed to contain memorable, distinct and easy-to-type English words. It is used under the Creative Commons Attribution 3.0 license.