The strongest password is one nobody chose: a long string drawn at random from a large set of characters. This generator builds such passwords on your own device using the browser’s cryptographically secure random number generator, and it tells you exactly how strong each setting is, in bits of entropy and in estimated cracking time.
How to use the password generator
- Set the length. 16 to 24 characters is a good range for most accounts.
- Choose how many passwords to create, up to 20.
- Tick the character types to include: uppercase, lowercase, digits and symbols.
- Optionally avoid look-alike characters and require at least one of each selected type (many websites demand this).
- Press Generate passwords. Press it again for a fresh batch. Copy the one you want into a password manager.
Each batch comes with a strength readout for the settings used, so you can compare the effect of adding length or character types by changing one setting and generating again.
Password entropy formula
L is the length and N the size of the character pool: 26 uppercase + 26 lowercase + 10 digits + 27 symbols = 89 here. Each character drawn uniformly from 89 symbols adds log₂ 89 ≈ 6.48 bits.
Requiring at least one character of each type removes the strings that miss a type, so the calculator subtracts that small amount using inclusion–exclusion. The average time to crack is half the search space divided by the attacker’s guessing speed:
Worked example
With the default settings — 20 characters, all four types, at least one of each:
- Pool size: 26 + 26 + 10 + 27 = 89 characters.
- Raw entropy: 20 × log₂ 89 = 20 × 6.4757 ≈ 129.51 bits.
- The one-of-each rule rules out about 9.5% of strings, which costs about 0.14 bits, leaving 129.37 bits — rated very strong.
- At 10 billion guesses per second, a rate a well-equipped attacker can reach against a fast, unsalted password hash, the average search takes about 1.4 × 10²¹ years.
How length and character sets compare
| Password type | Entropy | Average crack time at 10¹⁰ guesses/s |
|---|---|---|
| 8 lowercase letters | 37.6 bits | about 10 seconds |
| 8 characters, all types | 51.8 bits | about 2.3 days |
| 12 characters, all types | 77.7 bits | about 390,000 years |
| 16 lowercase + digits | 82.7 bits | about 12.6 million years |
| 16 characters, all types | 103.6 bits | about 2.5 × 10¹³ years |
| 20 characters, all types | 129.5 bits | about 1.5 × 10²¹ years |
Adding four characters gains more than switching on every character type. That is why current guidance favors length.
Password best practices
Use a password manager
Random passwords are impossible to memorize across dozens of accounts. A password manager stores them, fills them in, and lets you use a unique password everywhere, so one breached website cannot unlock the others.
Follow modern guidance
NIST’s Digital Identity Guidelines (SP 800-63B) put length ahead of composition rules, recommend screening new passwords against lists of known-breached ones, and advise against forced periodic changes. The current revision asks for at least 15 characters when a password is the only sign-in factor.
Turn on multi-factor authentication
Even a perfect password can be phished. An authenticator app or a hardware security key stops most account takeovers that a stolen password alone would allow.
Entropy assumes true randomness
These numbers apply only to passwords produced by a random generator like this one. Human-chosen passwords, even long ones with symbols, follow patterns that attackers’ dictionaries and rules exploit, so their real strength is far lower than the formula suggests.
For numeric codes, try the PIN generator; to check a password field’s length limit, use the character counter.
Frequently asked questions
Is this password generator safe to use?
Yes. Passwords are created in your browser with crypto.getRandomValues, the operating system's cryptographically secure random number generator, and they are never sent over the network or stored by CalcFluent. For extra caution, you can generate a password with your network disconnected.
How long should my password be?
For a randomly generated password, 16 characters using all four character types gives about 104 bits of entropy, far beyond any practical brute-force attack. Use 20 or more for master passwords and encryption keys. Length matters more than complexity.
What does entropy in bits mean?
Entropy measures how many equally likely passwords the generator could have produced. Each extra bit doubles the number of guesses an attacker needs. A 20-character password from an 89-symbol pool has about 129 bits of entropy, or roughly 10³⁸ possibilities.
Why avoid look-alike characters?
Characters such as I, l and 1, or O and 0, are easy to misread when typing a password from paper or another screen. Excluding them lowers entropy slightly per character, so add a character or two of length to compensate.
Do I need to change passwords regularly?
Current NIST guidance says no: forced periodic changes tend to produce weaker, predictable passwords. Change a password when there is evidence it has been exposed, and use a unique password for every account.