How this password generator works
Each password is built from random choices made by your browser's built-in cryptographic random number generator (the Web Crypto API), the same facility used for security features on the web. It is not the weaker Math.random function that some simple generators use. To avoid a subtle statistical bias, the generator discards random values that would make some characters slightly more likely than others. It also guarantees that at least one character from every type you have selected appears, then shuffles the result so those guaranteed characters are not predictable positions. The password exists only in your browser tab. It is not sent over the network, logged or stored.
What makes a password strong?
Length and unpredictability matter most. Every extra character multiplies the number of possible passwords, and randomness means an attacker cannot narrow it down using patterns such as words, names, dates or keyboard runs. The strength figure shown under the password is an entropy estimate: the length multiplied by the base-2 logarithm of the number of possible characters. It is a rough guide to how large the search space is, not a promise about how long a real attack would take, which depends on how the website stores passwords and what the attacker has.
Practical advice for using generated passwords
- Use a different password for every account. When one site is breached, reused passwords let attackers try the same login elsewhere.
- Store them in a password manager. A random 16-character password is not something to memorise. Reputable password managers, including the ones built into major browsers and operating systems, can save and fill them.
- Prefer length. If a site allows it, 16 characters or more is a sensible default for important accounts such as email, banking and your password manager itself.
- Turn on two-factor authentication wherever it is offered, because it protects you even if a password leaks.
- Never share passwords through email or chat, and be wary of any page that asks for one unexpectedly.
Options explained
Selecting more character types increases the pool and therefore the entropy per character. Some websites reject certain symbols or require specific types, so you can switch types on or off to match their rules. The "avoid look-alike characters" option removes I, l, 1, O, 0 and o, which is useful if you will ever need to read the password aloud or type it from a printout, at the cost of a slightly smaller character pool.
A note on trust
Because the generator is plain JavaScript that runs locally, you can verify it works offline: load the page, disconnect from the internet and it will still produce passwords. Even so, after you copy a password, paste it straight into your password manager or the sign-up form, and clear the clipboard if you are on a shared computer.