How to generate a strong password
- Choose a length — 16 characters is a strong default.
- Select the character types to include. More variety means more strength per character.
- Optionally exclude look-alike characters if you'll need to read or type the password manually.
- Click Generate, then Copy and save it in your password manager.
How secure are these passwords?
Every character is chosen with crypto.getRandomValues(), the browser's cryptographically secure random number generator, using rejection sampling so no character is more likely than another. The password is created on your device and never sent over the network. We guarantee at least one character from each type you select, then shuffle the result.
Password strength and entropy
With all four character types (87 characters), each character adds about 6.4 bits. A 16-character password has about 103 bits of entropy — at a trillion guesses per second, cracking it by brute force would take far longer than the age of the universe.
| Password | Approx. entropy | Verdict |
|---|---|---|
| 8 lowercase letters | 38 bits | Very weak — cracked in seconds offline |
| 10 mixed + digits | 60 bits | Okay for low-value accounts |
| 12 all types | 77 bits | Good |
| 16 all types | 103 bits | Excellent |
Password best practices
- Use a unique password for every account. Reuse is the main way breaches spread.
- Use a password manager so you only have to remember one strong master password.
- Turn on two-factor authentication, especially for email, UPI apps and net banking. Prefer an authenticator app over SMS where possible.
- Avoid personal details — names, birthdays, mobile numbers and vehicle numbers are the first things attackers try.
Developers storing passwords should never keep them in plain text or hash them with fast algorithms — see the hash generator page for why.
Frequently asked questions
Are these passwords safe to use?
Yes. They're generated in your browser with the Web Crypto API's cryptographically secure random number generator, and they're never transmitted or stored. Close the tab and they're gone.
How long should my password be?
At least 12 characters for everyday accounts and 16 or more for email, banking and password-manager master passwords. Length adds more strength than complexity.
What does entropy mean?
Entropy measures unpredictability in bits. Each extra bit doubles the guesses an attacker needs. Around 60 bits resists online attacks; 80+ bits is strong against offline cracking; 100+ is excellent.
Should I reuse a strong password?
Never. If one site is breached, attackers try the same email and password everywhere. Use a unique password for every account and a password manager to remember them.
Last updated: 22 September 2026Suggest an improvement · Report a problem
