jakup

2-+?_uKz_NCYS6-N

StrengthVery strong · ~100 bits

Passwords are generated in your browser and never sent to a server.

16

Include

Recent passwords

No saved passwords yet.

History is stored only in this browser. Clear it after use on shared computers.

What makes a password strong

Password strength comes from the number of possible combinations, not from how complicated it looks. With the same character set, adding one more character helps far more than sprinkling in a symbol. Length beats forcing in every character type.

The biggest risk is reuse. When one site is breached, every account sharing that password goes with it. Use a different password per site, and if that is too much to remember, let a password manager hold them. Turn on two-factor authentication for the accounts that matter.

Passwords here are produced by your browser’s cryptographic random generator and never sent to a server. Bear in mind that the moment you send one through chat or email a copy exists there — save it straight into your manager rather than keeping it in a screenshot or a note.

Frequently asked questions

Should I change my passwords every few months?

Forced rotation is no longer advised. When people must change a password every 90 days they just bump the trailing number, which makes the result easier to guess. The NIST guidance dropped scheduled expiry and now says to change only on signs of a breach. Start long and unique instead.

How do I know this page is not storing what it generates?

You can check for yourself. Open the network tab in your browser developer tools, press generate, and you will see no request leave the page. The tool also works with your connection switched off entirely, because everything happens inside the browser.

How long should a password be?

If a manager will hold it, you never type it, so 20 characters or more is a sensible default. For something you must type by hand, around 16 is practical. The slider here runs from 4 to 64, and the bit figure shown below the result tells you how many combinations you are getting.

Is saving passwords in the browser good enough?

It is far better than reusing one password everywhere. The drawbacks are moving between devices and browsers, and the fact that an unlocked machine exposes the lot. If you use several devices or share accounts with family, a dedicated manager is easier. Unique per site matters most.

Do passkeys make passwords unnecessary?

Not yet. A passkey signs you in with a key held on your device, which resists both breaches and phishing, but support is still patchy across services. Move the sites that support it to passkeys, and for the rest pair a long password with two-factor authentication.

Can I delete the list of generated passwords?

Yes, the clear button removes it. The recent list keeps at most 20 entries and lives only in this browser, never on a server. Even so, on a shared or borrowed machine it is worth turning the saving option off, or clearing the list before you walk away.