Create strong, random passwords with your preferred length and character options. The calculator shows password strength, entropy bits, and estimated time to crack. All generation happens in your browser with no data sent to any server.
A strong password is one that can't be guessed, looked up, or brute-forced in any practical amount of time. The single biggest factor in password strength is length, followed by the character set used. A 16-character random password drawn from 95 printable ASCII characters has about 105 bits of entropy — orders of magnitude beyond what current and foreseeable computing can brute-force.
This generator creates passwords using the browser's cryptographic random number generator (window.crypto.getRandomValues), which is the same source security-sensitive code uses. Nothing is sent to any server. You choose the length and character classes (uppercase, lowercase, digits, symbols), and the generator produces a password along with an entropy estimate and time-to-crack figure based on standard offline-hash assumptions.
Combine a strong generated password with a password manager (1Password, Bitwarden, Apple Keychain, etc.) and you've solved most of the practical password-security problem for individual accounts. The remaining risks — phishing, credential stuffing from breaches at sites you don't control — are addressed with two-factor authentication and unique passwords per site.
16 characters, all classes enabled Example output: K9#mp2$xRq7nVw4! Entropy: ≈ 105 bits Brute-force time: practically infinite at current speeds Store this in a password manager; don't try to remember it.
For passwords you need to type frequently (laptop login, password manager master password), a 4–6 word random passphrase is easier to remember than random characters and can be just as strong: correct-horse-battery-staple-bonus ≈ 65 bits entropy if words are truly random from a large list Combine with 2FA for very strong security.
Use this any time you create a new account or change a compromised password. Store the result in a password manager rather than a sticky note or text file.
The minimum length to use for different contexts: - Forum or low-stakes site you might never visit again: 12+ chars - Banking, government, healthcare: 16+ chars - Email (because it controls password resets everywhere else): 20+ chars - Password manager master password: 24+ chars OR a long random passphrase
Pair every generated password with 2FA where supported. NIST guidance (SP 800-63B) supports very long passwords without forced-rotation, and discourages mandatory complexity rules — but real-world account security depends more on uniqueness per site and 2FA than on any specific character recipe.
Calculate subnet mask, network address, broadcast, and usable host range from CIDR.
Convert colors between HEX, RGB, and HSL formats.
Calculate download time from file size and internet speed.
Calculate aspect ratio from width and height, or find missing dimensions.
Convert between bytes, KB, MB, GB, TB, and PB.
Calculate pixels per inch from screen resolution and display size.
D_sD2ngx+YzT{@ObStrength
Very Strong
Entropy
103 bits
Crack Time
Billions of years+
| Detail | Value |
|---|---|
| Password Length | 16 characters |
| Character Set Size | 88 characters |
| Entropy | 103.4 bits |
| Strength | Very Strong |
| Crack Time (10B/sec) | Billions of years+ |