🌐 English
User Guide - Methods and Boundaries

Whether a random password is good or bad cannot be judged solely by whether it contains symbols.

Distinguish between random sources, character sets, lengths, and usage patterns; understand tools using transparent computational methods, rather than labeling passwords as absolutely secure.

Content verified: 2026-10-08 · Edited by: Site maintainer

What do length and uniqueness solve respectively?

Longer, randomly generated passwords increase the guessing space, while using different passwords for different accounts prevents a leak in one place from directly affecting other accounts. These are two dimensions: reusing a seemingly complex password while still binding multiple accounts together.

This site only generates new passwords and does not require you to enter your existing passwords. After generating a password, please save it to a password management method you trust and enable additional login verification according to the capabilities provided by your account service. This tool does not estimate "how many years it will take to crack" because attack conditions, speed limits, and password storage methods are not controlled by this page.

How does this tool generate random characters?

The random numbers are generated from the browser's Crypto.getRandomValues. The tool first filters out random bytes that could cause modulo-division bias, then extracts characters from your selected character set; when multiple character sets are selected, it only accepts results where each selected character set appears at least once. The length range is 8 to 128.

You can choose uppercase letters, lowercase letters, numbers, and symbols listed on this site. Different services accept different symbols, so you should check the requirements of the target service before registering; do not assume that deleting unacceptable characters will make it completely identical to the original generation rule.

Why not provide a universal strength score?

For a character sequence that is independently and uniformly selected and has no other constraints, the number of candidates is a power of the length of the character set size, and its logarithm helps to understand the search space. This tool also requires all selected character groups to appear, which constrains the candidate set; therefore, the first version does not display the simple logarithmic formula as the actual security strength.

Even a correct random source cannot prevent phishing, malicious extensions, device compromise, or screen leaks. Clicking copy after generation will automatically write the data to the system clipboard; the clipboard may be read by other apps on the device, and cross-device synchronization depends on system settings. Only copy when you intend to use it.

Local processing scope

The page code does not send the generated password to the server, nor does it record it in local persistent storage. It remains in the results area of ​​the current page until you regenerate, clear, or close the page; do not display the results when sharing your screen. The server will still process the regular web logs generated by the page visit; see our privacy policy for details.

After use, you can click "Clear Results" to reduce visible residue on the page; this does not equate to clearing the system clipboard or other application records. To check local behavior, view your browser's network panel: the generation operation should not increase requests to send passwords to the server.

References

The links are for verifying technical definitions; the examples and operational suggestions are compiled by this site and do not masquerade as actual project evaluations.

Return to the tool and try a set of parameters.