fast&private

Secure Password Generator

Generate random passwords with the length and character types you choose.

Your data is never sent to any server.

Characters Passphrase

The secure password generator creates random passwords with the length and character types you choose. Each one is generated with your browser’s cryptographic generator and comes with its estimated strength and how long it would take to crack. Nothing you generate leaves your device.

How much length matters

Strength depends on two things: the size of the alphabet and, above all, how many characters are drawn from it. With lowercase, uppercase and numbers (62 symbols):

LengthEntropyTime to crack
8~48 bitsabout 20 minutes
12~71 bitsabout 500 years
16~95 bitsbillions of years

These are the times the tool shows, worked out for an attacker with a powerful graphics card who has stolen a poorly protected database.

Going from 8 to 12 characters counts for vastly more than adding symbols to an 8-character one. If you have to choose between meeting a symbol requirement and making the password longer, make it longer.

The substitution myth

Swapping letters for lookalike symbols (writing “password” as “p4ssw0rd”) does not work: attack dictionaries have applied those same substitutions automatically for decades. A disguised word is still a word, and it falls just as fast.

The only thing that adds real security is the password being genuinely random, picked by a generator rather than by a person. That is why it belongs in a manager instead of in your memory.

How to use Password Generator

  1. 1

    Set the length

    Slide the control between 8 and 64 characters. At least 16 is the recommendation for accounts that matter.

  2. 2

    Pick the character types

    Turn on uppercase, lowercase, numbers and symbols according to the service's rules. The more types you include, the larger the alphabet the password is drawn from.

  3. 3

    Generate the password

    Press Generate another if you want a different one. The strength meter and the estimated crack time update with every change.

  4. 4

    Copy it into your manager

    Use the copy button and save it in your password manager before closing the page.

Frequently asked questions

Is it safe to generate passwords on a website?

In this tool yes, because the password is generated in your own browser using the system's cryptographic generator (crypto.getRandomValues) and is never sent over the network.

How long should a secure password be?

At least 12 characters, and 16 or more for critical accounts such as email or banking. Each extra character multiplies the search space by the size of the alphabet, so difficulty grows very fast.

Should I always include symbols?

It is worth it when the service accepts them, since they widen the possible alphabet. If a site rejects them, make up the difference with extra length, which counts for considerably more.

What are ambiguous characters and when should I exclude them?

The ones that get confused when read or dictated, such as 0 and O, or 1, l and I. Excluding them lowers the strength slightly, but it pays off if you are going to type the password from paper or read it out over the phone.

How is the strength calculated?

From the entropy, which combines the length with the size of the enabled alphabet. It is computed from the settings rather than the particular string produced, because what makes a password strong is the space it was drawn from, not how it happens to look.

Where does the crack time come from?

It assumes the realistic worst case: someone has stolen the database of a service that stored passwords with a fast hash, and tries 100 billion combinations per second with a graphics card. Against a normal login with a limit on attempts, it would take vastly longer.

Where should I store the generated passwords?

In a password manager (Bitwarden, 1Password, KeePass and so on). They let you use a unique, strong password for every service without having to memorise any of them.