Password Generator

Create secure passwords with entropy analysis.

Generated Password

-
Entropy: - bits
Strength: -
Online Crack Time: -
Offline Crack Time: -

What is a Password Generator?

A password generator creates random strings of characters that are far harder to guess or crack than anything a person would invent. Humans pick predictable patterns — names, birthdays, dictionary words — and attackers try those first. A generator has no such habits: every character is drawn evenly from the pool you select.

This tool builds passwords from four character sets — uppercase letters, lowercase letters, numbers, and symbols — with an optional filter that removes ambiguous look-alikes such as the letter O and the digit 0. For each password it reports the entropy in bits, a strength rating, and estimated crack times for two attack scenarios.

Everything runs locally in your browser — the password is never transmitted or stored anywhere.

How Password Strength Is Calculated

Strength is measured in bits of entropy. Each character drawn from a pool of size N contributes log2(N) bits, and the total grows linearly with length. Crack time then divides that search space by the attacker's guessing speed:

Entropy (bits) = Password Length × log2(Character Pool Size)

Crack Time = 2^Entropy ÷ Guesses Per Second

  • Password Length — the slider value, from 4 to 128 characters. Every extra character multiplies the possibilities by the full pool size.
  • Character Pool Size — the sum of the enabled sets: 26 uppercase + 26 lowercase + 10 digits + 26 symbols = 88 characters when all four are on.
  • Guesses Per Second — the assumed attack speed: 10 billion per second for an online attack against a rate-limited login page, and 100 billion per second for an offline attack on a leaked password hash.

The crack time shown exhausts every combination; an attacker succeeds after searching half the space on average. The strength meter maps entropy to four bands: below 40 bits is Weak, 40 to 59.9 is Fair, 60 to 79.9 is Good, and 80 bits or more is Strong.

Worked Example: A 16-Character Password with All Sets Enabled

With the default settings — length 16, all four sets checked — the pool holds 88 characters, so each character adds log2(88) ≈ 6.4594 bits. The calculation runs end to end like this:

  • Entropy: 16 × 6.4594 = 103.4 bits, comfortably in the Strong band.
  • Total combinations: 88^16 = 12,933,699,143,209,908,517,669,873,647,616 — about 1.29 × 10^31, or 12.9 nonillion passwords.
  • Offline crack time: 1.29 × 10^31 ÷ 100,000,000,000 guesses per second ≈ 1.29 × 10^20 seconds ≈ 4.1 trillion years.
  • Online crack time: ten times longer, roughly 41 trillion years — and real login systems lock or throttle accounts long before that.

Contrast that with an 8-character password from the same pool: entropy falls to 8 × 6.4594 = 51.7 bits, and the offline crack time collapses to about 10 hours. Halving the length removed 51.7 bits, shrinking the search space by a factor of 2^51.7 — roughly 3.6 quadrillion. Length is the single most powerful lever you have.

Entropy and Crack Time by Length

What the calculator reports at common lengths, assuming all four character sets (pool size 88):

LengthEntropyOnline Crack TimeOffline Crack Time
851.7 bits4.2 days10.0 hours
1064.6 bits88.3 years8.8 years
1277.5 bits683,888.7 years68,388.9 years
1490.4 bits≈5.30 billion years≈529.6 million years
16103.4 bits≈41.0 trillion years≈4.10 trillion years
20129.2 bits≈2.46 × 10^21 years≈2.46 × 10^20 years

How to Use

  1. Drag the Length slider to choose 4–128 characters. The current value appears next to the label and defaults to 16.
  2. Check the character sets you want: Uppercase (A-Z), Lowercase (a-z), Numbers (0-9), and Symbols (!@#...). At least one set must stay selected.
  3. Optionally tick Exclude Ambiguous to drop i, l, 1, L, o, 0, and O — handy when the password will be read aloud or typed by hand.
  4. Click Generate for a new password. One is created automatically when the page loads.
  5. Review the entropy, strength rating, and online/offline crack-time estimates below the password.
  6. Click Copy to copy the password to your clipboard.

Frequently Asked Questions

What is password entropy?

Entropy measures randomness in bits: password length times log2 of the pool size. Every extra bit doubles the combinations an attacker must try, so a 103-bit password is about a million times harder to crack than an 83-bit one.

How is crack time estimated?

We assume 10 billion guesses per second for online attacks and 100 billion for offline attacks on a leaked hash. The figure shown is the time to try every combination — 2^entropy divided by the guessing rate — and an attacker succeeds in about half that time on average.

Should I exclude ambiguous characters?

If you need to type the password manually or read it over the phone, excluding similar-looking characters reduces typing errors. The trade-off is small: the pool shrinks from 88 to 80 characters, so a 16-character password drops from 103.4 to 101.2 bits of entropy — a loss of about 2.2 bits that leaves it firmly Strong.

How long should my password be?

Aim for at least 12 characters for everyday accounts and 16 or more for email, banking, and anything that guards other credentials. Length beats complexity: a 16-character password with all sets enabled reaches 103.4 bits of entropy, while an 8-character one manages only 51.7 bits even with symbols included.

Are passwords generated here safe to use?

Yes for most purposes. Generation happens entirely in your browser and nothing is sent over the network. For your most critical accounts, consider a reputable password manager: it uses a cryptographically secure random source and stores a unique password for every site, removing the temptation to reuse them.

How often should I change my passwords?

Current guidance favors changing passwords only when you suspect a breach, not on a fixed schedule. Forced periodic changes push people toward predictable tweaks like appending another digit. What matters more is a unique, strong password for every account.