Random Password Generator

Generate a strong random password with your chosen character types and length.

What actually makes a password strong

Password strength is measured in entropy — the number of guesses an attacker would need on average. Entropy depends on two things: how large the pool of possible characters is, and how many characters you use. Length contributes far more than complexity, because entropy grows exponentially with length but only logarithmically with the size of the character set. A long passphrase of ordinary words typically beats a short string of symbols, and is considerably easier to remember.

This is why current guidance from bodies including NIST has moved away from forced complexity rules and mandatory periodic changes. Those rules pushed people towards predictable patterns — a capital at the start, a digit and an exclamation mark at the end — which attackers model easily. What matters more is that each password is unique to one account, because the most common way accounts are compromised is credential stuffing, where a password exposed in one breach is tried everywhere else. A password manager and two-factor authentication do more for real security than any complexity rule, and a generated random password is only useful if you are not retyping it from memory.

Frequently asked questions

Is length or complexity more important?

Length. Entropy grows exponentially with length but only logarithmically with character-set size, so a long passphrase generally beats a short complex string, and is far easier to remember.

Should I change my passwords regularly?

Current guidance says no, unless there is reason to believe one is compromised. Forced periodic changes lead to predictable minor variations, which are weaker than a single strong password kept until there is cause to change it.

Why does reusing a password matter so much?

Because of credential stuffing: attackers take passwords exposed in one breach and try them across other services. A unique password per account confines any single breach to that one account.

Are password managers safe?

They are considerably safer than the realistic alternative of reusing or writing down passwords. They allow a unique strong password per account behind one strong master password, ideally with two-factor authentication enabled.