Explanation
How Passwortgenerator works
The password generator creates random passwords directly in the browser using the Web Crypto API (crypto.getRandomValues). You determine the length, count and which character groups are used — upper/lowercase letters, digits and special characters.
The display length × log₂(pool size) models the theoretical search space. The actual generation additionally guarantees at least one character from each active group; the bit value therefore does not describe this distribution exactly and is neither proof of security nor a prediction of concrete attack times.
A strongly generated password does not protect against reuse, phishing, malware or insecure storage. Use each password only once and manage it with a secure solution suited to your use case.
Common mistakes
- Reading the bit value as a guarantee: It only describes a modelled search space and not the security of the entire account.
- Reusing passwords: A leaked password at one service compromises all accounts with the same password (credential stuffing).
- Math.random() instead of the Crypto API: Math.random() is not specified for cryptographic purposes. This tool uses crypto.getRandomValues() and discards edge values for uniform index selection.
- Patterns instead of true randomness: Human-devised "random" passwords contain systematic patterns (keyboard walks, leetspeak) that attackers know and test deliberately.
Limits of this tool
- The entropy display is the model length × log₂(pool size); the guaranteed group coverage is not represented exactly in it.
- No protection against phishing: even the strongest password does not help if it is entered on a fake site.
- No check against password leaks (e.g. Have I Been Pwned) — only regeneration, no validation of existing passwords.
- No passphrase mode — only random character strings. Use other tools for memorable passphrases.
Sources
- BSI – Creating secure passwords: Guidance on length, single use and secure management of passwords.
- NIST SP 800-63B-4: Current Digital Identity Guidelines on password requirements, blocklists and authenticators.
- OWASP Authentication Cheat Sheet: Best practices for password policies in web applications, incl. recommendation of a 64+ character maximum length.
- Web Cryptography Level 2 (W3C): Specification of crypto.getRandomValues() for cryptographically strong random values in the browser.