Password Generator
Very strong · about 103 bits of entropy from a pool of 88 characters
How this was worked out
- Character pool26 + 26 + 10 + 26 = 88 characters
- Bits per characterlog2(88) = 6.46
- Total entropy16 × 6.46 = 103 bits
- Search space88^16 ≈ 2^103 ≈ 10^31 passwords
The entropy figure assumes an attacker knows exactly which character sets were ticked and how long the password is — which is the honest assumption, because that is what every generator’s output advertises, and a secret alphabet is not a defence anyone should count on. It also assumes a uniform draw, and this is very nearly one: guaranteeing a character from each set you ticked rules out a sliver of the possibilities and leaves the rest very slightly uneven, so the true figure sits below the one shown. How far below depends on the length. At the sixteen characters this opens on it is about a third of a bit, and about one bit measured at the likeliest single password. The gap widens as the password shortens: at the four-character minimum with all four sets ticked the guarantee fixes one character of each kind, so there are 4,218,240 possible passwords rather than 88⁴ — nearly four bits less than the figure printed above. The randomness is crypto.getRandomValues, with no Math.random fallback anywhere — a browser that cannot provide it gets an error rather than a predictable password. Weak to Very strong are a convention here, not a standard. Nothing is uploaded, nothing is stored, and the password is never put in the address bar, so it cannot reach your browser history or a link you paste to someone.
Randomness a browser can actually vouch for
A password is only as good as the process that produced it. This generator draws every character from the browser’s cryptographic random number generator, which is designed to be unpredictable even to someone who knows every other password it has produced. It never uses Math.random(), which is fast, seeded and entirely predictable to an attacker who can observe a few outputs — fine for shuffling a playlist, disqualifying for generating a secret.
It is the character-by-character half of a pair. The passphrase generator draws whole words from a numbered list instead, which is the one to use for a secret you have to remember and type; this one is for a secret that lives in a password manager and never passes through your head.
How the strength figure is calculated
Strength is reported as entropy in bits: length × log2(pool size), where the pool is the total number of distinct characters available. With uppercase, lowercase, digits and symbols all enabled the pool is 88 characters — 26 + 26 + 10 + 26 — and log2(88) is about 6.46 bits per character.
| Length | Bits | Label the tool applies |
|---|---|---|
| 8 characters | 52 | Fair |
| 12 characters | 78 | Strong |
| 16 characters | 103 | Very strong |
| 24 characters | 155 | Very strong |
The labels come from fixed thresholds: anything under 40 bits is weak, under 60 fair, under 80 strong, and 80 or more very strong. A 16-character password at 103 bits means roughly 2^103 equally likely possibilities.
Length beats variety, and not by a little. Sixteen lowercase letters alone is 75 bits — within a hair of the 78 bits that twelve characters from all four sets provide, and far beyond the 52 bits of an eight-character password using every set available. Adding a symbol to a short password adds a few bits; adding four more characters adds twenty-six.
The options, and what they cost
Selecting a character type guarantees at least one of it, rather than leaving it to chance: one character is drawn from each selected set first, the rest are drawn from the combined pool, and the whole thing is shuffled so the guaranteed characters are not clustered at the front. This matters because many sites reject a password that happens to contain no digit.
"No look-alikes" removes the characters people confuse when reading a password aloud or copying it from a screen — 0 and O, 1 and l and I, and the vertical bar and quote marks. It shrinks the pool from 88 to 83, which costs about one bit on a 16-character password: 102 instead of 103.
One bit is a trivial price for a password you have to type into a television, and it is a much smaller price than the one you pay for retyping a character you misread.
What the entropy figure assumes
The bit count is only valid for a password generated exactly this way — uniformly at random from a stated pool. It is not a measure you can apply to a password a human invented. "Password1!" draws from the same 88-character pool and would score 65 bits on that formula, and it would be cracked instantly, because attackers do not guess uniformly at random. They start with leaked password lists, dictionary words, keyboard runs, substitutions like @ for a, and appended years.
The number also says nothing about what happens after generation. A strong password stored in a text file, reused across sites, or typed into a phishing page is compromised regardless of its entropy. Generate it here, put it straight into a password manager, and enable multi-factor authentication on anything that matters — the generator runs entirely in your browser and keeps no record of what it produced, so there is nothing to recover if you lose it.
Length, expiry and the manager that holds it
How long should a password be?
Sixteen characters from a full set is a sound default and lands around 103 bits. Twelve is acceptable for low-value accounts. Anything the password manager fills in for you may as well be 24 or 32, since you will never type it.
Should I change my passwords regularly?
Not on a schedule. Both NIST and the UK’s NCSC now advise against forced periodic expiry, because it pushes people toward predictable variations. Change a password when there is a reason to: a breach notification, a shared device, or any suspicion of compromise.
Are passphrases better than random strings?
They are easier to remember and can be just as strong, provided the words are chosen at random and there are enough of them — six random words from a large list comfortably exceeds 70 bits. A memorable sentence you composed yourself does not.
Last reviewed 27 August 2026