How to use the Password Generator
- Use the slider to set the password length. Use at least 12 characters, or 16 or more for important accounts.
- Choose which character types to use: uppercase, lowercase, numbers and symbols. Every password includes at least one character from each type you select.
- If you'll be writing the password down or reading it out to someone, turn on Exclude look-alike characters.
- Click Generate, then click the copy button next to the password you want to use.
What makes a password strong
A password is only as strong as it is hard to guess. That's measured as entropy, in bits. For a randomly generated password, entropy is length × log₂(number of possible characters). Each extra bit doubles the number of guesses an attacker needs.
| Character set | Characters | 8 chars | 12 chars | 16 chars |
|---|---|---|---|---|
| Numbers only | 10 | about 27 bits | about 40 bits | about 53 bits |
| Lowercase letters | 26 | about 38 bits | about 56 bits | about 75 bits |
| Upper + lowercase + numbers | 62 | about 48 bits | about 71 bits | about 95 bits |
| Upper + lowercase + numbers + symbols (this tool) | 87 | about 52 bits | about 77 bits | about 103 bits |
As the table shows, making a password longer helps much more than adding character types. This tool rates passwords under 40 bits as "Very weak," under 60 as "Weak," under 80 as "Fair," 80 bits or more as "Strong" and 100 bits or more as "Very strong."
Why random passwords beat ones you make up
Passwords people make up tend to follow patterns: birthdays, names, keyboard runs like qwerty123, or a word with a number and an exclamation mark tacked on the end (Summer2024!). Attackers try lists of real leaked passwords and these common patterns first, so a password that looks long can still be cracked quickly.
Tooljip's password generator picks each character with your browser's crypto.getRandomValues. Unlike the ordinary Math.random, it's designed to be unpredictable. The tool also picks characters without bias, so no character shows up more often than the others.
How to keep your passwords safe
- Use a different password for every site. If one site is breached, every other account that shares the same password is at risk too.
- Nobody can remember dozens of random passwords. The practical answer is to store them in your browser's built-in password manager or in a dedicated password manager app.
- For email, banking and cloud accounts, turn on two-factor authentication (an authenticator app or text-message codes). That way a leaked password alone isn't enough to get into your account.
- For passwords you share with guests, like your Wi-Fi password, exclude look-alike characters when you generate it. Then share it with a Wi-Fi QR code so nobody has to type it by hand.
- Never send passwords by email or chat if you can avoid it. If you must share one, send it separately from the username and change it afterward.