Password Generator

Generate strong random passwords and passphrases with the length and characters you choose.

 

–

What makes a password strong?

A strong password is long and truly random. Attackers don't guess passwords one by one by hand; they use software that tries billions of combinations, starting with common words, names and patterns. A random password avoids all of those patterns, so the only way to crack it is to try every possibility.

PasswordEntropyStrength
8 lowercase letters38 bitsWeak
12 mixed characters75 bitsStrong
16 mixed characters100 bitsVery strong
5-word passphrase52 bitsFair
7-word passphrase72 bitsStrong

Password tips

  • Use a password manager so you only need to remember one strong passphrase.
  • Turn on two-factor authentication for important accounts.
  • Never reuse passwords between sites.
  • Change a password straight away if a service tells you it was involved in a data breach.

Passphrases use the EFF Short Wordlist by the Electronic Frontier Foundation, licensed under CC BY 3.0 US.

Frequently asked questions

Are these passwords safe to use?

Yes. Passwords are generated in your browser with its cryptographically secure random number generator (the Web Crypto API). They're never sent to a server or stored, so no one else ever sees them.

How long should my password be?

At least 12 characters for everyday accounts, and 16 or more for important ones such as email, banking and your password manager. Length adds more strength than complexity does.

What is a passphrase?

A passphrase is several random words joined together, like “stump-fiber-quiet-otter-drift”. Five or six random words are as strong as a complex password but far easier to remember and type.

What does “entropy” mean?

Entropy measures how unpredictable a password is, in bits. Every extra bit doubles the number of guesses an attacker needs. Around 60 bits is reasonable for most accounts and 80 bits or more is very strong.

Should I reuse a strong password?

No. If one site leaks it, attackers try it everywhere else. Use a different password for every account and keep them in a password manager.