What makes a password strong?
A strong password is long, random and unique. Length matters most: every extra character multiplies the number of possible combinations. Randomness stops attackers from guessing with word lists, names or birthdays. Unique means you use it nowhere else, so a data breach at one website does not expose your other accounts.
Passwords such as Welcome123!, Summer2026 or your dog's name tick the usual boxes (capital, number, symbol) but sit at the top of every list attackers try. A random 16-character password is practically uncrackable.
How strong is your password? Entropy explained
The strength of a random password is measured in bits of entropy:
entropy = length × log₂(number of possible characters)
With lowercase, uppercase, digits and 25 symbols there are 87 possible characters. Each character adds log₂(87) ≈ 6.4 bits. A 16-character password therefore has about 103 bits of entropy: 2¹⁰³ possibilities, a 31-digit number.
| Entropy | Rating | Example |
|---|---|---|
| < 40 bits | weak | 8 lowercase letters |
| 40–59 bits | fair | 10 letters and digits |
| 60–79 bits | strong | 12 characters, all types |
| ≥ 80 bits | very strong | 16 characters, all types |
The calculator also shows the average time to crack the password at 10 billion guesses per second, which is a fast offline attack with powerful graphics cards on a leaked database. At 103 bits that takes far longer than the age of the universe.
Example
With the default settings (16 characters, all types) you get something like q}E97$@,uj}};KmE. Leave out look-alike characters (0, O, 1, l, I) and the password is easier to type from paper, at the cost of only a few bits. For sites that reject special characters, choose 20 characters without symbols: still about 119 bits.
How this generator works
- Characters are chosen with
crypto.getRandomValues(), your browser's cryptographically secure random generator, the same source used for encryption, not the predictableMath.random(). - Every character type you select appears at least once, so the password meets typical site rules.
- Nothing is sent to a server or stored. Once loaded, the page even works offline.
Tips for secure passwords
- Use a password manager. You only need to remember one strong master password; the manager stores and fills in the rest. Well-known options include Bitwarden, 1Password, KeePass and the managers built into Apple, Google and Firefox.
- Turn on two-factor authentication for email, banking and social media. Even if your password leaks, an attacker cannot simply log in.
- Never reuse a password. Your email password matters most, because it can reset all the others.
- Check for breaches with a service such as Have I Been Pwned and change exposed passwords immediately.
- Passphrases work too: four or five truly random words (for example umbrella-kiwi-volcano-tile-gull) are easy to remember and strong, as long as the words are chosen at random.
Guidance from NIST in the US and the National Cyber Security Centre in the UK points the same way: favour long passwords or passphrases, check them against known breached passwords, and don't force people to change strong passwords on a schedule.
Frequently asked questions
How long should a strong password be?
At least 12 characters, preferably 16 or more. For your password manager or email, use 20 characters or a five-word passphrase.
Is it safe to use an online password generator?
This generator runs entirely in your browser: the password never leaves your device and is not stored. Copy it straight into your password manager.
Which is better, symbols or a longer password?
Length counts most. A 20-character password of letters and digits beats a 12-character one with symbols. Use symbols when a site allows them.
Why leave out look-alike characters?
Characters such as 0 and O, or 1, l and I, are easy to confuse when you type or read out a password. Leaving them out avoids mistakes and weakens the password only slightly.
Should I change my passwords regularly?
Not if they are strong and unique. Do change a password immediately if you suspect it leaked or a service reports a breach.
Can I generate several passwords at once?
Yes, up to 20. The copy button puts them all on your clipboard, one per line.
Last reviewed: 2026-10-06. Results are estimates for information only.