What actually makes a password strong
One number decides it. That number is how many guesses an attacker has to make, which is the size of the alphabet raised to the length. This page shows you that sum instead of a colour.
Length does more work than variety. Twenty lowercase letters are stronger than ten characters with a symbol in them, because every extra character multiplies the work again. A rule that demands one of everything mostly makes passwords people cannot remember or type.
None of it matters if the randomness is weak. Math.random is not built for secrets, and someone who sees a few of its outputs can work out the ones that follow. This page uses crypto.getRandomValues, your browser's cryptographic random source.
- Randomness
- crypto.getRandomValues, drawn without bias. Never Math.random, which is guessable.
- Strength
- Entropy in bits, worked out from the alphabet and the length. The page shows the sum.
- Rules
- Avoid look-alikes, No repeated characters, and One of each kind. Avoiding look-alikes shrinks the alphabet, and the bits figure shows the cost.
- Nothing kept
- The page makes no request and keeps no log or history. Close the tab and the password is gone for good.
Where to keep it
Keep it in a password manager. A strong password you reuse everywhere becomes useless after one breach, and nobody remembers forty different ones.
The one password worth memorising is the one that unlocks the manager. Make that one long, and never type it into anything but the manager itself.