Security Tool

Password Creator

Cryptographically secure • Runs in your browser • Never transmitted

Generated
—
—
—
20
83264128
Character sets
Uppercase A B C … Z
Lowercase a b c … z
Numbers 0 1 2 … 9
Symbols ! @ # $ % ^ &
Exclude ambiguous 0 O l 1 I
Exclude similar { } [ ] ( ) / \
Cryptographically Secure
Uses crypto.getRandomValues() — the same randomness as OS key generation. Never predictable.
Word-based passphrases
Five English words selected at random from this 675-word list provide about 47 bits of selection entropy. Use more words for sensitive accounts.

Why This Generator Is Different

Cryptographically secure randomness

Most password generators use Math.random() — a pseudo-random function that is predictable with enough data. This generator uses the crypto.getRandomValues() API, the same cryptographic randomness used by operating systems for key generation. It is not predictable, not reproducible, and not influenced by the time of day or any observable state.

Why 20 characters is the new baseline

In 2024, consumer GPUs can test over 100 billion MD5 password hashes per second. An 8-character password with full charset falls in under an hour. A 12-character password falls in weeks. At 20 characters, brute force becomes computationally infeasible for any attacker without nation-state resources — we're talking millions of years even with future hardware improvements.

The NIST SP 800-63B guidelines (updated 2024) now explicitly recommend length over complexity, and remove mandatory rotation policies that were previously thought to improve security but actually caused users to make predictable incremental changes.

Passphrases — stronger than they look

Five English words selected at random from this 675-word list provide about 47 bits of selection entropy. Use more words for sensitive accounts. The key word is random: a passphrase like "correct-horse-battery-staple" (from XKCD 936) is strong precisely because the words were chosen randomly, not because they form a clever phrase you invented. Invented phrases have patterns that attackers can model.

What "exclude ambiguous" actually protects

Characters like 0 vs O, l vs 1 vs I look identical in many fonts. Excluding them has zero security cost (the charset loss is negligible at 20+ characters) but eliminates transcription errors when reading a password off a screen. Recommended whenever you might need to type the password manually.

Your passwords never leave this page

Generation runs entirely in your browser using JavaScript and the Web Crypto API. Generating a password does not send it over the network. No passwords are logged or transmitted. Some tools work locally in the current browser session. Checks that rely on external data require an internet connection.

Related tools

To test the strength of a password, use the Password Strength Checker. For questions about how this tool works, see the FAQ.