VSThiran

Technology & Developers

Free Password Generator

Create strong random passwords that never leave your browser.

Free to useNo sign-up requiredNo watermarkRuns in your browser

This free password generator creates strong random passwords using your browser's cryptographic random number generator - not the ordinary pseudo-random function most scripts reach for, which is not fit for anything security-related.

The password is generated on your device, is never transmitted, and is never stored. Reload the page and it is gone, so copy the one you want into your password manager before you leave.

How this tool works

  1. Set the length

    Sixteen characters or more is a sensible minimum. Length contributes far more strength than complexity does.

  2. Choose the character types

    Lower case, upper case, digits and symbols. Turn off anything a particular site refuses to accept.

  3. Generate and copy

    Five options are produced at once. Copy one straight into your password manager.

How it works

Characters are drawn using crypto.getRandomValues, the browser's cryptographically secure source of randomness. Math.random is never used - it is predictable enough that passwords built with it can be reconstructed.

Values from the top of the byte range are discarded rather than wrapped, so no character is more likely than any other. Skipping that step introduces a small but real bias that weakens the result.

Strength is reported as entropy in bits, calculated from the size of the character set and the length. Each extra bit doubles the effort needed to guess it.

Nothing is stored, logged or transmitted. There is no history, and closing the tab discards everything.

What actually makes a password strong

  • Length above everything. A sixteen-character password of only lower-case letters is far stronger than an eight-character one with symbols.
  • Randomness. A password you invented follows patterns you are not aware of. Substituting 3 for e and @ for a is the first thing cracking tools try.
  • Uniqueness. Reuse is what turns one breach into many. A unique password per site limits the damage to that one account.
  • A password manager, so unique random passwords are practical to actually use.
  • Two-factor authentication wherever it is offered - it protects the account even if the password is exposed.

Entropy, roughly translated

Under 40 bitsTrivially guessable with modern hardware
40 to 60 bitsWeak; adequate only for throwaway accounts
60 to 80 bitsReasonable for most everyday accounts
80 to 110 bitsStrong; suitable for email and banking
Over 110 bitsVery strong; appropriate for master passwords and keys

Worked examples

A master password

Twenty-four characters with all types enabled gives well over 110 bits - appropriate for the one password protecting everything else.

A password you must type by hand

Turn on "avoid look-alike characters" so 0 and O, 1 and l cannot be confused, and go longer to make up for the smaller alphabet.

A site that rejects symbols

Turn symbols off and add a few characters of length instead - the strength is easily recovered.

Frequently asked questions

Is this password generator free?

Yes, free with no sign-up and no limit on how many passwords you generate.

Are the passwords sent anywhere or saved?

No. They are generated in your browser, never transmitted and never stored. There is no history and no log - reload the page and they are gone permanently.

How random are they really?

They use crypto.getRandomValues, the browser's cryptographically secure generator, with rejection sampling so that no character is favoured. This is the same class of randomness used for encryption keys.

How long should my password be?

At least sixteen characters for ordinary accounts, and twenty or more for email, banking and password manager master passwords. Length matters more than symbol variety.

Should I change passwords regularly?

Current guidance says no - forced rotation pushes people towards predictable variations. Change a password when there is a reason to: a breach, a shared device, or any suspicion of exposure.