// security
Password Generator.
Generate cryptographically random passwords with configurable length, character sets, and optional passphrase mode. Uses crypto.getRandomValues for true randomness.
Passwords
Why Strong Passwords Matter
Every year, billions of credentials are exposed through data breaches at major websites and services. When you reuse a password across multiple accounts, a single compromise can cascade into full identity theft, financial loss, and unauthorized access to your email, cloud storage, and social media. Attackers don't target individuals one by one; they purchase massive leaked credential databases and run automated attacks against every popular platform. A weak password like qwerty123 or password will be cracked in seconds. A reasonably strong one can resist these attacks for years or even centuries, depending on its entropy.
Brute-force attacks try every possible combination of characters until the correct password is found. The time this takes depends entirely on how many combinations exist. A password made of only lowercase letters and six characters long has roughly 309 million possibilities, which modern hardware can exhaust in under a second. Extend that to sixteen characters using all character classes and the number of possibilities explodes into the quadrillions, making brute-force computationally infeasible with current technology.
Password Entropy and Length
Entropy is the measure of how unpredictable a password is, measured in bits. Each additional bit of entropy doubles the number of possible combinations an attacker must try. A password with 40 bits of entropy has roughly one trillion possibilities; 60 bits pushes that to one quintillion. The single most effective way to increase entropy is to make the password longer. Every extra character multiplies the search space by the size of the character set. Going from twelve to sixteen characters with the same character set increases entropy by roughly 25 percent or more.
Security researchers generally recommend a minimum of twelve characters for everyday accounts and sixteen or more for high-value targets like email, banking, and admin panels. The tool above defaults to twenty characters precisely because the marginal cost of a longer password is near zero while the security gain is substantial. Modern password managers can store and autofill long random strings so you never have to memorize them, removing the practical barrier that once limited password length.
Random Characters vs. Passphrases
There are two dominant approaches to generating strong passwords. Random character strings like k9$Tm2xLpQ8vWn4j maximize entropy per character and are virtually impossible to guess. The downside is that they are hard to remember, so they work best when stored in a password manager. Passphrases combine several random words into a sequence like correct-horse-battery-staple. They are easier to type and remember because the words form a mental image, and each word adds significant entropy when drawn from a large word list.
The trade-off is that passphrases require more characters to achieve the same entropy as a random string. A four-word passphrase with a 2048-word dictionary provides roughly 44 bits of entropy, while a twelve-character random string using all character classes provides about 78 bits. For most online accounts where a password manager is available, random characters offer superior security. For situations where you must memorize the password and cannot use a manager, a passphrase of six or more words strikes a practical balance between security and usability.
Character Sets and Their Trade-offs
The password generator lets you toggle four character sets: lowercase letters (a through z), uppercase letters (A through Z), digits (0 through 9), and symbols. Each set you enable increases the pool of characters available for each position, directly raising the password's entropy. Lowercase only provides 26 possibilities per position. Adding uppercase doubles that to 52. Including digits brings it to 62, and adding a common symbol set pushes it to roughly 95.
However, not all character sets are equally practical. Some websites and services impose restrictive password policies that reject symbols or limit maximum length. Others use case-insensitive comparisons, effectively halving the benefit of mixed case. Before generating a password for a specific service, check its requirements. The tool's toggles let you tailor the output to match those constraints while still maximizing entropy within the allowed set. If a service supports all four sets, enable them all for the strongest possible password per character of length.
Best Practices for Password Security
Never reuse passwords across accounts. If one service is breached, attackers will immediately try those same credentials on banking, email, and social platforms. Use a reputable password manager to generate and store a unique random password for every account. Enable two-factor authentication wherever available; even if your password is compromised, the second factor provides a critical additional layer of defense.
Treat your email password as the crown jewel. If an attacker gains access to your email, they can trigger password resets on every other account. Make it the longest and strongest password you have. Periodically audit your accounts using services like Have I Been Pwned to discover which credentials have appeared in known breaches, and change them immediately. Avoid security questions with easily guessable answers like your mother's maiden name or childhood pet; use random strings as answers and store them in your password manager just like passwords.
FAQ
What is the recommended password length for online accounts in 2026?
NIST now recommends 12+ characters as a minimum, with no mandatory special-character rules; use a passphrase of 4-5 random words for memorability + length.
Why shouldn't I use `Math.random()` to generate passwords?
It's not cryptographically secure and can be predicted — use `crypto.getRandomValues()` in browsers or `secrets.token_urlsafe()` in Python for real randomness.
Are password managers' built-in generators better than online ones?
Yes — 1Password, Bitwarden, and KeePassXC generate passwords locally (never sent to a server) and integrate with autofill; safer than online tools for daily use.
Should I include special characters in generated passwords?
Length matters more than character variety — a 16-char all-letters password beats a 10-char mixed-symbol one; modern guidance prioritizes length over complexity rules.
What is the entropy of a random 16-character password?
With 95 printable ASCII chars: log2(95^16) ≈ 105 bits — way beyond brute-force range; a random 12-char password gives ~78 bits, still unbreakable.