QR Code Generator
Styled QR codes with colors, a center logo and SVG export.
Utilities & Converters
Cryptographically random passwords with a live entropy meter.
Length beats complexity. Each additional character multiplies the search space; adding a symbol to a short password barely moves it.
| Length | Character set | Entropy | Offline crack time (10¹² guesses/sec) |
|---|---|---|---|
| 8 | lower + digits | 41 bits | ~35 minutes |
| 8 | all 94 printable | 52 bits | ~2 months |
| 12 | all 94 printable | 79 bits | ~19 million years |
| 16 | all 94 printable | 105 bits | effectively forever |
| 4 words | diceware list | 52 bits | ~2 months |
| 6 words | diceware list | 78 bits | ~9 million years |
| 7 words | diceware list | 90 bits | effectively forever |
The practical recommendation for 2026: 16 characters minimum for anything you type rarely and store in a manager, or a 6-word passphrase for anything you must type by hand — a device login, a password manager master password, a disk encryption key.
Entropy measures how many guesses an attacker needs, expressed in bits. Each bit doubles the search space, so 60 bits is not twice as strong as 30 bits — it is a billion times stronger.
It is calculated as log₂(pool size) × length. A 12-character password from the 94 printable ASCII characters gives log₂(94) × 12 ≈ 78.7 bits.
The critical condition is that the password must actually be random. "P@ssw0rd123!" has 12 characters from a 94-character pool, which naively computes as 78 bits — but it is in every cracking dictionary and falls in under a second. Entropy only counts if the selection was genuinely random, which is exactly what a generator provides and a human choosing a memorable password does not.
For anything you have to type from memory, yes. For anything stored in a password manager, it makes no difference.
A passphrase built from randomly selected dictionary words — the Diceware method — gets its entropy from the word list size, not the character count. A 7,776-word list gives 12.9 bits per word, so six words is 77.5 bits: comparable to a 12-character random password, and vastly easier to remember and type on a phone or a TV remote.
The requirement is that the words be chosen randomly by the generator. Picking six words yourself produces something close to a sentence, and human-chosen word sequences follow predictable patterns that cut the effective entropy by more than half.
The XKCD "correct horse battery staple" example is four words at 44 bits, which was reasonable in 2011 and is marginal now. Use six.
Because it is not random enough for anything security-relevant, and a surprising number of online password generators use it.
Math.random() is a pseudorandom number generator optimized for speed. In V8 it uses xorshift128+, seeded from a limited entropy source, and its internal state can be recovered from a modest number of observed outputs. Given a few generated values, an attacker can predict every subsequent one.
crypto.getRandomValues() draws from the operating system’s cryptographically secure entropy pool — /dev/urandom on Unix, BCryptGenRandom on Windows — which is designed to be unpredictable even to an adversary who has seen prior output.
This tool uses the latter, with rejection sampling to avoid the modulo bias that would otherwise make some characters marginally more likely than others. It is a small detail, and it is the difference between a uniform distribution and a slightly skewed one.
On this one, yes, because generation happens in your browser with Web Crypto and nothing is transmitted. Verify it yourself in the Network tab. A generator that produces passwords on a server is a category of tool to avoid.
They help, but less than length. Adding four characters to the length increases entropy more than adding the full symbol set to a short password. Some systems also reject certain symbols, which is its own annoyance.
Only when there is reason to — a breach, a shared credential, or a suspicion of compromise. NIST withdrew the routine-expiry recommendation in 2017, because forced rotation pushes people toward predictable incremental changes.
16 characters random, or 6 words as a passphrase, both comfortably exceed what is brute-forceable. Beyond that you are protecting against nothing that exists.
Yes, and this is more important than length. Credential stuffing — replaying a password leaked from one breach against every other service — is the most common account compromise route by a wide margin.
No. They exist in the page memory until you navigate away. Nothing is logged, saved or transmitted.
Software that stores unique passwords behind one master password. Yes — it is the only practical way to have a different strong password everywhere. Use a passphrase for the master password.