What makes a password strong
Password strength comes from how many possible passwords an attacker would have to try. Two things matter: length and the number of different characters you use. Each extra character multiplies the possibilities, so length beats complexity.
| Length | Characters | Entropy | Rating |
|---|---|---|---|
| 8 | Letters + numbers | ≈ 48 bits | Fair |
| 12 | Letters + numbers + symbols | ≈ 77 bits | Strong |
| 16 | Letters + numbers + symbols | ≈ 103 bits | Very strong |
| 20 | Letters + numbers + symbols | ≈ 129 bits | Very strong |
The generator shows the entropy of every password, measured in bits. Each extra bit doubles the number of guesses needed.
Is it safe to use an online password generator?
This one never sends your passwords anywhere. They're created on your device with your browser's cryptographically secure random number generator (the Web Crypto API), and they're never included in the page's HTML or stored on a server.
For the same reason, results aren't saved automatically. If you star a password, it's kept in your own browser's storage; for real accounts, a password manager is the better place.
Password tips
- Use a different password for every account. Reused passwords are the main way one breach turns into many.
- Aim for 16 characters or more for important accounts like email and banking.
- Store them in a password manager rather than a note or spreadsheet.
- Turn on two-factor authentication wherever it's offered. It protects you even if a password leaks.
Frequently asked questions
What is a passphrase, and is it as safe as a random password?
Are the passwords stored or logged?
Why avoid look-alike characters?
How long should my password be?
last updated