Strong Password Lab

Free strong password generator

Build a genuinely strong password — long, random, and unpredictable — generated locally with crypto.getRandomValues(). No server calls, no tracking, no storage.

Strong Password Generator

Cryptographically random passwords built to resist brute-force, dictionary, and pattern-based guessing.

••••••••••••
16

🔒 This tool runs 100% offline in your browser. We cannot see, save, or transmit anything you generate or type here.

What Actually Makes a Password Strong

"Strong password" is one of those phrases that gets said so often it stops meaning anything. So it helps to be specific. A password is strong when an attacker's software cannot get to it through a reasonable number of guesses. Two things decide that: how many characters it has, and how unpredictable they are.

The maths, roughly

Take 12 random letters and numbers. There are 62 possible characters at each position, so the total number of combinations is about 3 followed by 21 zeros. Now assume an attacker has serious hardware and can test a hundred billion guesses every second, which is the kind of speed you only get when they have stolen a database and are attacking it offline. Even then, working through every combination would take around a thousand years.

Add symbols and stretch the password to 16 characters, and the number of combinations climbs past 10 to the power of 31. That is not a slightly better password. It is out of reach for anyone. And that is a random password. Length only helps when the characters are truly unpredictable, which is where people slip up.

What attackers actually try

Nobody sits and tries "aaaaaaaa" then "aaaaaaab". Cracking tools start with lists of real leaked passwords, then common words, then those words with the usual tweaks: a capital first letter, a 1 for an l, a number or a year at the end. A sixteen character password made of a real word and a couple of digits falls quickly, because it follows the same shape thousands of others do.

This is why a shorter fully random password can beat a longer human-chosen one, and why the old advice to swap an "a" for an "@" has faded. Attackers know that trick too.

Where the stolen database comes from

The offline cracking scenario above assumes an attacker already has your hashed password in hand, and it's worth understanding how that happens, because it isn't usually your fault at all. A company you have an account with gets breached, and its database of user passwords, stored as hashes rather than plain text if they followed basic practice, ends up circulating on hacking forums or gets published outright. At that point the attacker isn't guessing at your login page anymore, where rate limits and lockouts would slow them down; they're running cracking software against the stolen hash on their own hardware, completely outside your control and outside the company's. Strength is what determines how that particular fight goes, and it's the one part of this you actually have leverage over. You can't stop a company from being breached, but a strong, unique password decides whether that breach costs you anything.

Symbols matter less than you think

Symbols help, but length does more of the work. A long password made of letters and numbers only is fine, and sometimes necessary, because plenty of sites still choke on certain symbols. If one rejects your password, untick symbols and add a few more characters. You lose very little strength and gain a password that actually saves.

Strong is not the same as safe

A perfect password can still be stolen. If you type it into a fake login page, a strong password will not save you. If you use it on two sites and one is breached, the attacker simply tries that same password on the other. This is called credential stuffing, and it is behind a large share of account takeovers.

  • Use a different password everywhere. The main password generator makes that quick.
  • Turn on two-factor authentication wherever it is offered, starting with your email and your social accounts.
  • Check the address bar before typing a password, especially after a link in a message.

Password, passphrase or PIN?

The three suit different places. A dense random password is for logins you paste from a manager. A passphrase, several random words strung together, is for the few secrets you type by hand, like the manager's own master password. Our passphrase generator builds these. A PIN is a short number for a keypad or lock screen where the device limits your guesses, and the numeric PIN generator is made for that. None is safer in general. Each is safer where it belongs.

A sane setup

Here is the version that works for most people. One password manager. One passphrase to unlock it. A generated password of 16 characters or more for every account, saved automatically. Two-factor authentication on the accounts that matter most. That is really all of it, and it takes an afternoon to set up.

A few situations have their own rules. A router key is best generated with the WiFi password generator and shared with visitors using a QR code. If a site demands an exact length, use the 12 and 15 character generator. And when the thing you need is a token or key for software, use the random string generator instead of a password.

Do you need to change it every few months?

Older advice said to rotate every ninety days regardless of anything else, and most current guidance, including NIST's, has dropped that requirement. Forced rotation on a schedule tends to make passwords weaker in practice, since people under pressure to change something that already works usually just increment a number or swap one character, which is a pattern crackers check for as readily as anything else. A strong, unique, randomly generated password doesn't get weaker by sitting still. What should trigger a change is a specific event: a service tells you it was breached, you notice a login you didn't make, you shared the password with someone who no longer needs it, or you used it somewhere else and that other site got compromised. Outside of those, a generated password left alone is doing exactly what it's supposed to.

Using this generator

Set the length with the slider (8 to 64, starting at 16), tick the character types you want, and press Generate. The strength meter gives an estimate based on length and character variety. It is a rough guide, not a promise, since it cannot know whether a site has been breached.

The password is built in your browser from a secure random source. To check that, open the Network tab in your browser's developer tools and generate a few. Nothing goes out. Copy the result straight into your manager and you are done.

Frequently Asked Questions