Password Generator
Generate strong, random passwords with adjustable character sets.
What makes a password strong?
Password strength depends on two factors: length and character set size. Together, these determine the number of possible passwords an attacker must try in a brute-force attack. The number of possible passwords is character set size^password length. A 16-character password using uppercase, lowercase, and digits (62 characters) has 62^16 = ~4.7 × 10^28 possible values — which would take millions of years to brute-force at a trillion guesses per second.
This generator uses the browser's crypto.getRandomValues() API, which produces cryptographically secure random numbers suitable for security-sensitive applications. This is fundamentally different from Math.random(), which is a pseudorandom number generator and should never be used for security purposes.
A good password for a general account should be at least 16 characters with mixed character types. For accounts with high sensitivity (banking, email, admin panels), use 20+ characters or a passphrase of 4+ random words (a "diceware" passphrase like "correct-horse-battery-staple" is both memorable and cryptographically strong). Always use a different password for every account and store them in a password manager.
Common mistakes
- Reusing passwords — A strong password is useless if used on multiple sites. When one site is breached, all your accounts with that password are compromised.
- Using Math.random() in code — Never use JavaScript's Math.random() to generate passwords or security tokens in your own code. Use crypto.getRandomValues() or crypto.randomUUID().
- Short passwords with complex requirements — An 8-character password with all character types is far weaker than a 20-character password with only letters. Length beats complexity.