Other Calculators

Password Generator

Generate high-entropy, cryptographically secure passphrases and random strings with custom rules.

Parameters & Inputs

Summary & Breakdown

Secure Generated Password
Very Strong 105.1 bits of entropy

Security Strength Analysis

Pool Character Size: 94 characters
Total Combinations: ~10^32
Brute-Force Crack Time: > 1 Trillion Years
Overview

About the Password Generator

In modern cybersecurity, automated credential stuffing and dictionary attacks crack weak passwords in fractions of a second.

A truly secure secret key requires mathematical entropy€”meaning every character is selected independently with uniform probability from a large character pool using hardware entropy.

This generator uses the client browser's native Web Cryptography API (`crypto.getRandomValues`), ensuring that strings are created locally without ever transmitting secrets over a network.

Mathematical Method

How the Calculations Work

Draws cryptographically random bytes via Web Crypto API, maps them uniformly across the selected character set pool, and calculates informational entropy using Shannon's formula: E = L * log2(N).

Entropy (bits) = Length * log2(Pool Size)

Variables & Definitions

  • Length: Total number of characters in the generated string
  • Pool Size: Total distinct selectable characters (up to 94)
  • Entropy: Bits of randomness (128 bits is standard for military encryption)
Plain-English Worked Example

A 16-character password using lowercase, uppercase, numbers, and symbols draws from a pool of 94 characters. Entropy = 16 * log2(94) = 16 * 6.55 = 104.9 bits of entropy.

Terminology

Key Terms Explained

Password Entropy

The mathematical measure of unpredictability in a secret string, measured in bits.

Web Crypto API

W3C cryptographic standard providing browser access to operating system hardware random entropy.

Brute-Force Attack

An automated attack systematically testing every possible combination until finding the correct password.

Credential Stuffing

Automated attacks attempting known stolen username and password pairs across different websites.

Best Practices

Practical Tips & Pitfalls to Avoid

1

Aim for at least 16 characters

Modern GPU password crackers make length far more protective than complex symbols alone.

2

Use a password manager

Store generated complex passwords inside an encrypted vault like Bitwarden or 1Password.

3

Never reuse passwords

A unique password for every web service prevents credential breaches on one site from endangering another.

4

Enable Multi-Factor Authentication (MFA)

Combine strong passwords with authenticator app 2FA for comprehensive account security.

Q&A

Frequently Asked Questions

Yes. Generation executes entirely inside your local browser using window.crypto. No passwords are sent to our servers.

Any password with over 80 bits of entropy resists online attacks; over 100 bits resists dedicated offline supercomputer brute-forcing.

Passphrases combining 4-5 random words (e.g., "correct horse battery staple") are easier to memorize while providing excellent entropy.

Because length exponentially expands the keyspace (Pool^Length). Adding 4 characters increases possibilities more than adding symbols to a short password.

Yes. Clicking Generate Password immediately creates a fresh cryptographic string.