// what makes a password generator "secure"?
Two things matter: randomness and entropy.
- Randomness: this tool uses
crypto.getRandomValues(), the Web Crypto API for cryptographically-secure random numbers. (For comparison,Math.random()is not cryptographically secure; its output is predictable enough that someone observing a few values can infer future ones, so it's unsuitable for generating passwords or tokens.) - Entropy measures how hard a password is to guess (in bits). ~60 bits is reasonable for personal accounts; ~80+ bits for important accounts; ~128+ bits is overkill for almost anything but feels good. A 16-character password using all four classes is ~104 bits.
Ambiguous-character filter: when checked, the generator excludes characters that look alike in some fonts (lowercase L vs digit 1, capital O vs digit 0, quote characters, etc.). Slightly less entropy per character, but eliminates the "is that an L or a 1?" annoyance for passwords you'll type by hand.
Privacy: passwords are generated entirely in your browser using the OS's underlying secure random number generator. They never touch the network. Close this tab and they're gone.
// a free, browser-only tool by Tiempo Software, built in Omaha, Nebraska. Runs entirely in your browser; nothing you enter is uploaded. see all tools.