Random passwords and passphrases, made on your device. This page never sends or saves them.
Words come from the EFF long word list of 7,776 words, available under CC BY 4.0 and served unmodified from this site.
Cracking tools try what people pick first: words, names, dates, keyboard patterns and passwords from past leaks.
A password drawn at random has no pattern to find. Its strength is simply the number of possibilities.
Your browser’s built-in cryptographic random generator picks every character and every word.
The page calls crypto.getRandomValues and discards any draw that would make one character or word more likely than another.
Entropy, counted in bits, is the size of the search: each extra bit doubles the number of possibilities an attacker has to try.
Times on this page assume 100 billion guesses a second, an offline attack on a fast hash, and give the average: half of all possibilities. A larger attacker is faster; a site that stores passwords with a slow hash such as bcrypt or Argon2 makes each guess far costlier. All figures are rounded down.
Average time at 100 billion guesses a second, rounded down. Characters are drawn freely from the chosen sets.
| Length | Numbers only | Lowercase | Upper & lowercase | All four sets |
|---|---|---|---|---|
| 8 characters | Under a second | 1 second | 4 minutes | 6 hours |
| 10 characters | Under a second | 11 minutes | 8 days | 6 years |
| 12 characters | 5 seconds | 5 days | 61 years | 51 thousand years |
| 16 characters | 13 hours | 6.9 thousand years | 450 million years | More than 1 trillion years |
| 20 characters | 15 years | 3.1 billion years | More than 1 trillion years | More than 1 trillion years |
Turn on two-factor authentication wherever it is offered, ideally with an authenticator app or a hardware key. Then match the rest of your privacy to your risk.
Find your level of protectionCurious about the math behind this? Read Password and Entropy: The Science Behind Your Security