TanodTools

Password generator

Strong random passwords, made in your browser and never sent or stored anywhere.

Runs entirely in your browser

Characters
    Entropy
    0
    Strength
    -
    Pool size
    0

    Passwords are generated in your browser and are never sent or stored. They disappear when you close or reload this page.

    Length 4 to 128 characters, and 1 to 50 passwords at a time.

    How to generate a strong password

    1. Set the length. For accounts you do not type often, 20 or more is a good choice.
    2. Pick which kinds of character to include, and whether to avoid look-alike characters.
    3. Copy a password, or copy the whole list. Press Generate again for new ones.

    What makes a password strong

    Strength comes from unpredictability and length, not from clever substitutions. A password picked uniformly at random from a large set of characters is as hard to guess as the arithmetic says: each character adds the base-2 logarithm of the pool size in bits of entropy, so a 20-character password from about 90 symbols carries roughly 130 bits, far beyond what any guessing attack can reach.

    Humans are poor random number generators, so this tool asks your browser's cryptographic random generator for the characters. To avoid a subtle bias, random numbers are drawn with rejection sampling: values that would make some characters slightly more likely are discarded and redrawn.

    The strength label is a plain guide based on entropy: under 40 bits is weak, 40 to 59 fair, 60 to 79 good, 80 to 99 strong, and 100 or more very strong. It assumes the password is used on one account only and the site stores it properly.

    Tips

    • Use a different password for every account and keep them in a password manager.
    • Need a random identifier instead? Try the UUID generator.
    • Sharing a Wi-Fi login? Put it in a QR code.

    Questions

    Are the passwords sent anywhere or saved?

    No. They are generated on this page using your browser's secure random number generator, and they are never sent over the network or stored. Only your option choices (length and which sets are on) are remembered in this browser, never the passwords. Closing or reloading the page discards them.

    How random are they?

    The tool uses crypto.getRandomValues, the browser's cryptographically secure generator. Characters are picked with rejection sampling so that no character is more likely than another.

    What does the entropy figure mean?

    Entropy in bits is the length times the base-2 logarithm of the number of possible characters. Each extra bit doubles the number of guesses an attacker needs. It assumes the password is truly random, which it is here, but it does not account for a site that stores passwords poorly.

    What does "at least one from each set" do?

    It makes sure each kind of character you ticked appears at least once, because some sites insist on it. The tool generates a password and discards it if a set is missing, so the result is not biased towards particular positions.

    Why avoid look-alike characters?

    I, l, 1, O, 0 and o are easy to confuse when you have to read a password aloud or type it from paper. Removing them makes the pool slightly smaller, which is shown in the entropy figure.

    Should I use a password manager?

    Yes. A random password is only useful if you can store it, and a password manager lets you use a different one for every account. This page does not store anything for you.