"At least 8 characters with upper, lower, a number and a symbol" โ stop inventing them, pick one here
How to use it
- Choose a tab: Random, Passphrase or PIN. Random opens first.
- On the Random tab, drag the length slider (8โ64) and tick the character types you need. Five fresh passwords appear every time you change something. Turn on Skip look-alikes if you will read the password out loud or type it from paper.
- Tap a line, or its copy button, to put it on the clipboard. The bar next to each one is its strength; the text below is how long a brute-force attack would take.
- Passphrase joins four to six random English words. It is long, which is what matters, yet easy to remember and to type on a phone.
- PIN gives you 4- or 6-digit codes for door locks, cards and app locks.
- The Check a password box at the bottom rates any password you type: length, character types, entropy and estimated crack time. Nothing you type there leaves your browser.
Everything runs locally with crypto.getRandomValues. No password is logged, and refreshing the page discards them, so copy what you want to keep.
Length beats complexity
A password's strength comes far more from how long it is than from how many character types it mixes. Sixteen lowercase letters (about 75 bits) beat eight characters drawn from every type (about 52 bits) by a wide margin. Adding four more letters helps more than forcing in a symbol.
The standards agree. NIST's digital identity guidelines (SP 800-63B) ask for a minimum of eight characters, encourage long passphrases, and specifically advise against forced composition rules and scheduled password changes. This generator's default of 16 characters clears that bar comfortably.
| Avoid | Birthdays, phone numbers, names, keyboard walks (qwerty, 1q2w3e4r), repeats (aaaa1111), one dictionary word plus a digit (apple1) |
|---|---|
| Fine | 12+ random characters, four or more unrelated words, a sentence only you would type |
| Most important | A different password for every site. One breach otherwise opens every account that shares it |
Estimated crack times
The table assumes ten billion guesses per second, roughly what a few GPUs manage against a fast hash. Sites that use a slow hash (bcrypt, Argon2) push these numbers up by thousands; sites that store passwords in plain text make them meaningless.
| 8 chars, digits only | 0.01 s |
|---|---|
| 8 chars, lowercase | about 21 s |
| 8 chars, all four types | about 7 days |
| 12 chars, lowercase | about 3.7 years |
| 12 chars, all four types | about 150,000 years |
| 16 chars, all four types | about a trillion years |
| 5-word passphrase from a 300-word list | under a second if the list is public โ add words or a number |
The on-screen rating is the entropy in bits, log2 of (alphabet size to the power of length): under 40 is weak, under 60 fair, under 80 strong, above that very strong. Passphrases are rated by the number of possible word picks, which is deliberately conservative.
Matching a site's rules
| Symbol required | Tick Symbols. Every generated password contains at least one of each ticked type. |
|---|---|
| Symbols not allowed | Untick Symbols and add about four characters of length; 12 alphanumerics beat 8 with symbols. |
| Maximum length | Set the slider to the limit. Banks and government sites often cap at 16 or 20. |
| Must start with a letter | Turn on Don't start with a symbol. |
| No spaces | Keep the passphrase separator as a hyphen, underscore or dot. |
Keeping passwords safe
- One per site. Use your browser's or OS's password manager, or a dedicated one, and feed it 32+ character random passwords.
- Turn on two-factor authentication for email, banking and social accounts. A leaked password alone then is not enough.
- Check for breaches. Look your email up on a breach-notification service and change any password that shows up.
- Scheduled changes are not required. Change a password when there is a reason to, not on a calendar; bumping the trailing digit each month makes it weaker.
FAQ
Does this site store the passwords it makes?
No. Generation and checking happen in your browser's JavaScript; there is no code that sends them anywhere, and they never appear in the URL.
Is a passphrase safer than a random password?
At equal length, random wins. But a passphrase can be much longer and still memorable, so a 20-character phrase usually beats a 12-character random string. Use random for anything stored in a manager, a passphrase for what you type by hand.
How many digits should a PIN have?
Six if allowed. A four-digit PIN has only ten thousand combinations. Avoid years, birthdays and repeated digits.
Related tools
- QR Code Generator โ share a Wi-Fi password as a QR code instead of spelling it out.
- What Is My IP โ compare a suspicious login alert with your own address.
- Character Counter โ check a password against a site's length limit.