🔐 Password Generator
Generates random passwords using crypto.getRandomValues() — your browser's
cryptographic random number generator. Nothing is sent anywhere; refresh the page and every
password is gone.
How the bits are counted
With all four sets ticked the pool is 88 characters: 26 lowercase, 26 uppercase,
10 digits and the 26 symbols !@#$%^&*()-_=+[]{};:,.<>?/.
Characters are drawn with rejection sampling, so there is no modulo bias, and the
badge reports:
bits = length x log2(pool)
16 x log2(88) = 16 x 6.4594 = 103 bits
Excluding the ambiguous l 1 I O 0 trims the pool to 85 and costs
0.05 bits a character: 102.6 instead of 103.4 over 16 characters. Cheap, if you
will ever read the password off a screen.
The two option checkboxes
- Require at least one of each set exists for sites that reject anything else. It constrains the output, so it very slightly lowers real entropy rather than raising it - negligible at length 16, but at the 4-character minimum the true figure is 22 bits against the 26 the badge shows.
- A Fisher-Yates shuffle scatters those required characters, so the first four positions are not predictably one per set.
- Length is the whole game: each character added is 6.46 more bits.
Frequently asked questions
How long should a random password be?
16 characters from the full pool is 103 bits, beyond any offline attack. 12 gives 78 bits and is fine for ordinary accounts. Below 10 you are in range of rented GPUs against a fast hash.
Is it safe to use a password generator in a browser?
The randomness is sound: crypto.getRandomValues() is the
operating system CSPRNG, not Math.random(). What no web page can
promise is the machine around it - extensions, clipboard history and screen
recorders see whatever you generate.
Why do sites still demand a capital and a symbol?
Habit. NIST removed composition rules from SP 800-63B because they push people to predictable patterns like Spring2024! rather than genuine randomness. Tick the box when a site insists, and add length instead when it does not.