Password generator
Strong, random passwords, created in your browser. Nothing you generate is sent or stored.
Your new password
Very strong · 129 bits of entropy · would take trillions of years to crack by brute force
How it works
What makes a password strong?
A strong password is one an attacker can't guess, even with a computer trying billions of combinations a second. Three things decide that: length, randomness and uniqueness.
- Length matters most. Every extra character multiplies the number of possible passwords by the size of the character set, so a 20-character password isn't a bit stronger than a 10-character one, it is billions of billions of times stronger.
- Randomness is what makes the length count. "Summer2024!" is 11 characters long but follows a pattern attackers try first. A password picked by a secure random generator has no pattern to exploit.
- Uniqueness protects you when a website is breached. Attackers try leaked email and password pairs on other sites within hours, so a reused password is only as safe as the weakest site you used it on.
How this generator works
PwdForge uses your browser's crypto.getRandomValues(), the cryptographically secure random number generator also used for encryption keys. Characters are picked with rejection sampling, so every character is exactly as likely as every other, with no bias towards the start of the alphabet.
The password is created on your device and never leaves it. There is no server involved, nothing is logged, and closing the page erases it. That is also why the page works offline once it has loaded.
How long should a password be?
The table shows how long it would take, on average, to brute-force a random password using all four character types, assuming a well-equipped attacker trying 100 billion guesses a second against a leaked password database.
| Length | Entropy | Time to crack |
|---|---|---|
| 8 characters | 52 bits | About 5 hours |
| 10 characters | 65 bits | About 4 years |
| 12 characters | 78 bits | About 34,000 years |
| 16 characters | 103 bits | Trillions of years |
| 20 characters | 129 bits | Trillions of years |
Online attacks, where someone types guesses into a login form, are far slower because sites limit attempts. The real danger is a breach: once a site's password database leaks, attackers can guess offline at full speed. A 16-character random password stays safe even then.
Keep your passwords in a password manager
Nobody can remember dozens of random passwords, and you shouldn't try. A password manager stores them encrypted, fills them in for you and warns you about reused or leaked passwords. Most browsers and phones include one, and there are good independent options too. Protect it with a strong, memorable passphrase and turn on two-factor authentication.
For more practical advice, read how to create a strong password.
Frequently asked questions
Is it safe to use an online password generator?
It is safe when the password is created on your own device and never sent anywhere, which is how PwdForge works. The password is generated by your browser's cryptographically secure random number generator and exists only on this page until you copy it.
How long should my password be?
For accounts that matter, use at least 16 random characters; 20 or more is better and costs you nothing when a password manager fills it in. Length adds far more strength than swapping letters for symbols.
Do I need symbols in my password?
Symbols make each character harder to guess, but adding a few extra characters does the same job. Keep symbols on unless a site rejects them; if it does, turn them off and add four or five characters instead.
What does "bits of entropy" mean?
Entropy measures how many guesses an attacker would need, as a power of two. A password with 80 bits of entropy has 2^80 possibilities. Every extra bit doubles the work, so 80 bits is a million times harder to crack than 60.
Why does the password include at least one of each character type?
Many sites require at least one number, one capital letter and so on. PwdForge always includes one character from every type you select, then shuffles the password so those characters are not in predictable places.
Should I change my passwords regularly?
Current guidance from security agencies such as NIST and the UK NCSC is no: forced regular changes lead to weaker passwords. Change a password when you suspect it has leaked, and use a unique password for every account.
How do I remember a random password?
You don't have to. Store it in a password manager, which fills it in for you. For the few passwords you do need to type from memory, such as the password manager itself, use a passphrase made of random words.