About the Password Generator
Randomness comes from crypto.getRandomValues, the browser's cryptographically secure generator. Each character is chosen with rejection sampling: random 32-bit values above the largest multiple of the alphabet size are discarded, so every character is exactly equally likely. The common shortcut random % n slightly favours some characters (modulo bias).
Strength is shown as entropy: length × log2(alphabet size). A 20-character password over the 90 characters of upper case, lower case, digits and symbols has about 130 bits. As a guide, under 36 bits is very weak, 60 bits resists online guessing, and 80+ bits is strong against offline cracking of fast hashes. “Require every selected class” redraws passwords that miss a class, which keeps them uniformly random among valid results. “Exclude ambiguous” removes look-alikes such as I l 1 O 0 o and hard-to-type punctuation.
Passphrase mode picks words from a built-in list of several hundred common English words. Each word adds about 9.3 bits, so six words give roughly 56 bits — easy to type on a phone and to remember. Increase the word count for anything protecting valuable data, and use a password manager for everything else.
How to use it
- Choose Password or Passphrase.
- Set the length (or word count) and the character sets.
- Pick how many to generate, then click Generate for a new batch.
- Copy one line or use “Copy all”.