What makes a password strong?
For a randomly generated password, strength depends on just two things: the length and the number of possible characters at each position. It is measured as entropy in bits: length × log2(character set size). Every extra bit doubles the number of guesses an attacker needs, so adding characters is the most effective way to make a password stronger.
| Character set | 8 chars | 12 chars | 16 chars | 20 chars |
|---|---|---|---|---|
| Digits only (10) | 27 bits | 40 bits | 53 bits | 66 bits |
| Lowercase only (26) | 38 bits | 56 bits | 75 bits | 94 bits |
| Upper + lower + digits (62) | 48 bits | 71 bits | 95 bits | 119 bits |
| Upper + lower + digits + 28 symbols (90) | 52 bits | 78 bits | 104 bits | 130 bits |
With the default settings (all four types, look-alikes excluded) the pool has 83 characters, so a 16-character password has about 102 bits of entropy. The strength label shown above the results uses this tool's own thresholds: under 40 bits very weak, under 60 weak, under 80 fair, under 100 strong, and 100 or more very strong.
These numbers only apply to truly random passwords. A password like Summer2026! uses all four character types but is easy to guess, because attackers try words, names, dates and common substitutions first.
Good password habits
- Never reuse passwords. When one site is breached, attackers try the same email and password on other sites (credential stuffing).
- Use a password manager. It remembers long random passwords for you, so you only need one strong master password.
- Turn on two-factor authentication or passkeys wherever they are offered, so a leaked password alone is not enough to log in.
- Avoid names, birthdays and dictionary words, even with numbers or symbols added.
Frequently asked questions
Are the generated passwords stored or sent anywhere?
No. Passwords are generated inside your browser with crypto.getRandomValues and are never sent to a server or logged. You can even disconnect from the network after the page loads and keep using it.
What does “exclude look-alikes” do?
It removes characters that are easy to confuse in many fonts, such as lowercase l, uppercase I, the digit 1, uppercase O, lowercase o and the digit 0 (and the | symbol). This helps when a password has to be read aloud or typed from paper, at the cost of slightly lower entropy.
How long should a password be?
Length matters more than complexity. A random 16-character password using letters, digits and symbols has over 100 bits of entropy, far beyond what can be brute-forced. If you use a password manager, 16 to 20 characters is an easy default.
A site does not accept some symbols. What should I do?
Either uncheck “Symbols”, or edit the “Symbols to use” field so it contains only the symbols that site allows (for example -_.). Every selected character type is guaranteed to appear at least once.