Generate Password

Click Generate to create a password
Password Length 16
🔠 Uppercase (A-Z)
🔡 Lowercase (a-z)
🔢 Numbers (0-9)
Symbols (!@#$)
Exclude Ambiguous (0,O,l,1)
🧠 Memorable Words

Quick Presets

Bulk Password Generator

Password Strength Checker

Enter any password to instantly check its strength. Your password is never stored or sent anywhere.

🛡️ Password Security Best Practices

Use at least 16 characters. Length is the single most important factor. A 16-char password with only lowercase is far stronger than an 8-char password with all character types.
🔀
Mix character types. Combine uppercase, lowercase, numbers, and symbols. This dramatically increases the number of possible combinations (the "charset size").
🔑
Use a unique password for every account. If one site is hacked and your password is exposed, attackers will try it on every other service. This is called "credential stuffing."
🗝️
Use a password manager. Tools like Bitwarden (free), 1Password, or LastPass securely store all your passwords. You only need to remember one master password.
📵
Never use personal information. Birthdays, names, phone numbers, and pet names are easy to guess - especially for people who know you or can find you on social media.
📖
Avoid common passwords. "password", "123456", "qwerty", "iloveyou" are the first things hackers try. Over 80% of data breaches involve weak or reused passwords.
Enable Two-Factor Authentication (2FA). Even if your password is stolen, 2FA prevents hackers from accessing your account without your phone or authenticator app.
Change passwords after breaches. Check haveibeenpwned.com to see if your email has appeared in data breaches. Change affected passwords immediately.
🧠
Use passphrases for master passwords. A random sequence of 4-5 words ("correct horse battery staple") is easy to remember but extremely hard to crack - stronger than most complex passwords.
Never share passwords via chat or email. Legitimate services will never ask for your password. Sharing via messaging apps is risky - use a secure password sharing feature in your password manager instead.

️ Most Common Passwords to NEVER Use

Password Security Math

Charset Size

Lowercase only (a-z): 26 characters
+ Uppercase (A-Z): 52 characters
+ Numbers (0-9): 62 characters
+ Symbols (!@#$%^&*...): 94 characters

Number of Possible Combinations

Combinations = Charset Size ^ Password Length

Example: 16-char password with 94 charset:
94^16 = 37,157,429,083,410,091,685,945,344 combinations
≈ 3.7 × 10^28 possible passwords

Password Entropy (bits)

Entropy measures unpredictability. Higher entropy = stronger password.

Entropy (bits) = log₂(Charset Size ^ Length)
= Length × log₂(Charset Size)

128-bit entropy is considered unbreakable.
A 20-char password with full charset has ~131 bits.

Time to Crack (Brute Force)

Crack Time = Combinations ÷ Guesses Per Second

Modern GPU: ~10 billion (10^10) guesses/second
Botnet: ~100 trillion (10^14) guesses/second

A 128-bit entropy password would take longer than
the age of the universe to crack even with a botnet.

Frequently Asked Questions

No - all generation is done entirely in your browser using JavaScript's cryptographically secure random number generator (window.crypto.getRandomValues). This API uses your operating system's cryptographically secure pseudorandom number generator (CSPRNG), the same source used for cryptographic operations. Nothing is transmitted to any server. Your passwords are completely private and never leave your device.
Four factors: (1) Length - every extra character multiplies possible combinations. Going from 8 to 16 characters is vastly more secure than adding symbols to an 8-character password. (2) Randomness - no patterns, words, or predictable substitutions (@ for a, 3 for e). (3) Character diversity - using uppercase, lowercase, numbers, and symbols increases the character set from 26 to 94. (4) Uniqueness - never reuse passwords across accounts. A 16-character fully random password with all character types is extremely strong.
Entropy (in bits) = length × log₂(charset size). Charset sizes: lowercase only = 26 (4.7 bits/char), + uppercase = 52 (5.7 bits/char), + numbers = 62 (5.95 bits/char), + symbols = 94 (6.55 bits/char). A 16-character full-charset password: 16 × 6.55 = 104.8 bits. At 1 trillion guesses/second: cracking takes approximately 4×10^13 years. 80 bits = strong. 100 bits = very strong. 128 bits = computationally unbreakable with foreseeable technology.
Adding symbols expands the 'charset' - the number of possible characters at each position. Without symbols: 62 possible characters per position (uppercase + lowercase + digits). With all printable ASCII symbols added: 94 possible characters. For a 16-character password: 62^16 vs 94^16. That's 4.7 × 10^28 vs 4.1 × 10^31 possible combinations - about 875 times more possible passwords just from adding symbols.
A passphrase is 4–6 randomly selected words: 'correct-horse-battery-staple.' Advantages: memorable without writing down, good entropy (4 random words ≈ 51 bits from the EFF wordlist). Best for passwords you must type from memory: computer login, password manager master password. Use character passwords (stored in password manager) for everything else - they give higher entropy per character. Critical: words must be genuinely random (dice rolls or generator), not 'phrases you like' which are predictable.
Change passwords when: (1) there is a known data breach at a service you use, (2) you suspect an account is compromised, (3) you shared a password with someone who no longer needs access, or (4) you reused a password that has been exposed. Do NOT change passwords on a fixed schedule (monthly, quarterly) unless required - frequent mandatory changes make people use weaker, more predictable passwords. NIST (US standards body) and most security researchers no longer recommend periodic forced changes.
2FA requires two independent proofs of identity: your password (something you know) and a second factor - typically a time-based one-time code from your phone (something you have). Even if a password is stolen in a breach, the attacker cannot log in without the second factor. Priority accounts for 2FA: email (controls account recovery for everything else), banking, social media, password manager. Use an authenticator app (Authy, Google Authenticator, Bitwarden Authenticator) rather than SMS - SMS can be intercepted via SIM swapping.
Yes - reputable password managers (Bitwarden, 1Password, Dashlane) are very safe and dramatically improve overall security. They encrypt your passwords with your master password using strong encryption (AES-256). Not even the company can see your stored passwords. The risk of a password manager being compromised is far smaller than the risk of reusing passwords across sites (credential stuffing attacks are one of the most common account takeover methods). Use a strong, memorable master passphrase and enable 2FA on the password manager itself.

Password Generator - What Makes a Password Truly Secure

Most people dramatically underestimate how fast modern password-cracking tools work. An 8-character password using only lowercase letters can be cracked in seconds. The same password with mixed case and numbers takes a few hours. A 16-character fully random password using all character types would take millions of years with current hardware. Length and true randomness are what matter - not adding "1!" to your pet's name.

How entropy works: A 16-character password using all 94 printable ASCII characters has entropy = 16 × log₂(94) = 16 × 6.55 = 104.8 bits. At 1 trillion guesses per second (current top-end hardware), cracking it would take longer than the age of the universe. A 12-character all-lowercase password has only 56 bits - crackable in a few months.

Password Strength at a Glance - What Each Level Means

Weak and Moderate Passwords

  • Very Weak (under 40 bits): Short, simple, or uses only one character type. Cracked in seconds to hours.
  • Weak (40–60 bits): 8–10 character mixed passwords. Vulnerable to dedicated attacks in hours to days.
  • Moderate (60–80 bits): 10–12 characters with full character set. Usable for low-risk accounts but not recommended for banking or email.

Strong and Very Strong

  • Strong (80–100 bits): 12–16 characters, fully random, all character types. Appropriate for most accounts.
  • Very Strong (100–128 bits): 16+ characters. Suitable for high-value accounts - email, banking, password manager.
  • Unbreakable (128+ bits): 20+ characters. Computationally impossible to brute-force with any foreseeable hardware.
  • 16 characters = recommended minimum for all important accounts.

Passwords vs Passphrases - When to Use Each

A passphrase is a sequence of 4–6 random dictionary words - "correct-horse-battery-staple" - rather than a string of random characters. They have some advantages for specific use cases:

  • Memorability: A 4-word passphrase is far easier to remember than "xK9#mP2@vQ7!nL4&". This matters for passwords you must type without a password manager - like your computer login or password manager master password.
  • Entropy: 4 truly random words from a 7,776-word wordlist (the EFF wordlist) give approximately 51 bits of entropy. 5 words give 64 bits. 6 words give 77 bits. This is comparable to a 10–12 character random character password.
  • Use random word selection: "ilovemycat" is not a passphrase - it's a predictable phrase. A passphrase must use genuinely random word selection, like rolling dice or using the generator above.
  • Character passwords are better when: Stored in a password manager (memorability doesn't matter, maximum entropy does), or required by a system with specific character requirements.

The Essential Password Security Rules

  1. Never reuse passwords. When one service is breached (and they are breached constantly), attackers try stolen credentials on every other major service. Unique passwords for every account limit breach damage to that one account.
  2. Use a password manager. The only realistic way to have unique, strong passwords for every account. Reputable options: Bitwarden (open-source, free), 1Password, Dashlane. Your master password should be a long, memorable passphrase.
  3. Enable Two-Factor Authentication (2FA) on all important accounts. Even if a password is compromised, 2FA requires a second factor - typically a time-based code from your phone. Use an authenticator app (Authy, Google Authenticator) rather than SMS 2FA where possible, as SMS can be intercepted.
  4. Check for breached accounts. Visit haveibeenpwned.com to see if your email address appears in known data breaches. If it does, change the password for that service immediately.
  5. Use long passwords, not complex short ones. "correcthorsebatterystaple" (25 characters, lowercase) is stronger than "P@ssw0rd" (8 characters with symbols). Length beats complexity.

How this calculator works, and where the numbers come from

The Password Generator applies the standard formula for this calculation to the values you enter and updates the result as you type. The calculation itself happens in your browser, and the page explains the method so you can check any result by hand.

Please note: Results are provided for general information and are calculated from the values you enter.

Sources and further reading

Last reviewed: by the CalcQube Editorial Team. See our editorial policy for how we build and check calculators, or report an error.