Generate a strong, random password using a secure random source.
Generates a random password using your browser's cryptographically secure random number generator (crypto.getRandomValues) — the same class of randomness used for encryption keys, not a predictable Math.random() function.
The password is generated on your device and never transmitted or stored anywhere.
Resistance to guessing comes overwhelmingly from length and randomness, not from cramming in symbols. Each extra random character multiplies the number of possibilities an attacker has to try:
P@ssw0rd add almost nothing — attackers try those first.Current NIST guidance drops forced complexity and periodic resets in favour of longer passwords and checking them against known-breached lists. The one rule that always holds: never reuse a password across sites.