What makes a password strong?
Password strength is measured by entropy — the number of bits of uncertainty an attacker faces. Each bit doubles the guesses needed. A password with 8 bits of entropy requires at most 2⁸ = 256 guesses to crack; one with 80 bits requires 2⁸⁰ ≈ 1.2 × 10²⁴ guesses — already a septillion guesses, and a 256-bit key's 2²⁵⁶ ≈ 1.2 × 10⁷⁷ is far beyond any practical brute-force attack.
Entropy is calculated as length × log₂(N) where N is the size of the character pool. Adding more character types increases N, but length is the dominant factor. Doubling the length squares the search space, while adding symbols to a 12-character password increases entropy by only ~7 bits.
Entropy reference table
- < 40 bits — Weak. Crackable in seconds by a consumer GPU. Common passwords, dictionary words, slight mutations.
- 40–60 bits — Medium. Crackable in hours to days. A long word with a few substitutions still falls here.
- 60–80 bits — Strong. Months to years of GPU time. A 12-character mixed-case + digits password lives here.
- 80+ bits — Very Strong. Centuries with current hardware. A 16-character truly random password easily exceeds this.
A 16-character password with all four character types (uppercase, lowercase, digits, symbols) has a pool of 91 characters in this generator: 16 × log₂(91) ≈ 104 bits — well into the "very strong" zone.
Best practices
- Use a password manager. Let it generate and store strong passwords for every site. You only need to remember one master password.
- Never reuse passwords. If one site leaks your credentials, attackers will try them everywhere (credential stuffing).
- Enable 2FA wherever possible. A strong password plus a second factor is exponentially harder to compromise.
- Avoid patterns. Don't use keyboard walks, common substitutions (p@ssw0rd), personal info, or known breaches.
- Length beats complexity. A 20-character lowercase-only password (≈94 bits) is stronger than a 10-character mixed-case+symbols one (≈66 bits).
- Check for breaches. Use Have I Been Pwned to see if your passwords have been exposed.
How the Password Generator Works
All passwords are generated entirely in your browser using crypto.getRandomValues() — a cryptographically secure random number generator backed by the operating system's entropy source. Nothing is sent to any server, logged, or stored. The code is a single self-contained HTML file you can inspect, save, and run offline.