What makes a password strong?
Length matters most. Each extra character multiplies the number of guesses an attacker needs. A random 16-character password with letters, digits and symbols has over 100 bits of entropy - far beyond what any current computer can brute-force. Entropy is shown under the password.
Best practices
- Use a different password for every account, so one breach does not unlock the rest.
- Store them in a reputable password manager rather than in your head or a file.
- Turn on two-factor authentication (an authenticator app or security key) for email, banking and anything important.
- Do not reuse a password with small variations like "Pass1", "Pass2".
- Never share passwords by email or chat.
How this generator works
It draws random numbers from crypto.getRandomValues with rejection sampling to avoid bias, guarantees at least one character from each selected type, and shuffles the result. Nothing is transmitted; close the tab and it is gone. Look-alike characters are excluded by default so passwords are easier to read and type.
Frequently asked questions
Is it safe to generate a password on a website?
This one runs entirely in your browser and makes no network requests for the password. You can even disconnect from the internet and it still works.
How long should my password be?
16+ characters for important accounts; use a manager so length is no burden.
Why avoid symbols sometimes?
A few sites reject certain symbols. Untick symbols and increase the length instead.