Skip to main contentSkip to calculator
108 calculatorsLive resultsStep-by-step solutions

Rechnerpilot tool

Password Generator

Generate passwords locally with browser cryptography, selectable character groups and a transparent search-space estimate.

Generators

Explanation

How Passwortgenerator works

The password generator creates random passwords directly in the browser using the Web Crypto API (crypto.getRandomValues). You determine the length, count and which character groups are used — upper/lowercase letters, digits and special characters.

The display length × log₂(pool size) models the theoretical search space. The actual generation additionally guarantees at least one character from each active group; the bit value therefore does not describe this distribution exactly and is neither proof of security nor a prediction of concrete attack times.

A strongly generated password does not protect against reuse, phishing, malware or insecure storage. Use each password only once and manage it with a secure solution suited to your use case.

Common mistakes

  • Reading the bit value as a guarantee: It only describes a modelled search space and not the security of the entire account.
  • Reusing passwords: A leaked password at one service compromises all accounts with the same password (credential stuffing).
  • Math.random() instead of the Crypto API: Math.random() is not specified for cryptographic purposes. This tool uses crypto.getRandomValues() and discards edge values for uniform index selection.
  • Patterns instead of true randomness: Human-devised "random" passwords contain systematic patterns (keyboard walks, leetspeak) that attackers know and test deliberately.

Limits of this tool

  • The entropy display is the model length × log₂(pool size); the guaranteed group coverage is not represented exactly in it.
  • No protection against phishing: even the strongest password does not help if it is entered on a fake site.
  • No check against password leaks (e.g. Have I Been Pwned) — only regeneration, no validation of existing passwords.
  • No passphrase mode — only random character strings. Use other tools for memorable passphrases.

Sources

  • BSI – Creating secure passwords: Guidance on length, single use and secure management of passwords.
  • NIST SP 800-63B-4: Current Digital Identity Guidelines on password requirements, blocklists and authenticators.
  • OWASP Authentication Cheat Sheet: Best practices for password policies in web applications, incl. recommendation of a 64+ character maximum length.
  • Web Cryptography Level 2 (W3C): Specification of crypto.getRandomValues() for cryptographically strong random values in the browser.

Practice

Practical examples

Secure standard passwords

With 18 characters and all character groups you get passwords with high entropy.

Numeric code

Disable letters and special characters if a service only accepts digits.

Readable passwords

Enable "Avoid similar" so that 0/O and l/1 are not confused.

FAQ

Frequently asked questions

Are the passwords stored?

No. The passwords are generated locally in the browser with crypto.getRandomValues() and never sent to a server. After closing the page they cannot be recovered.

What does entropy mean?

The display calculates length × log2(pool size) as a theoretical search space. Because at least one character of each active group is forced, it does not exactly describe the actual output distribution and is not proof of security.

Are special characters always necessary?

Not necessarily. Special characters enlarge the character pool, while additional length also increases the modelled search space. The target service's requirements are also decisive.

What does the option to avoid similar characters do?

It removes exactly 0, O, o, I, l and 1 from the character pool. This can help when typing manually and reduces the character pool accordingly.

How long should a secure password be?

The requirements depend on the service and its policy. More length enlarges the modelled search space when generated randomly; a fixed length is still not a general security guarantee.

Why should I use a separate password for every service?

Credential-stuffing attacks test leaked credentials on other services. Unique passwords limit this reuse risk, but do not guarantee the security of other accounts.

Is crypto.getRandomValues() secure enough?

The Web Crypto API specifies crypto.getRandomValues for cryptographically strong random values. This tool additionally uses rejection sampling so that the mapping to character indices does not receive a modulo bias.

Why does the generator show a colour for strength?

The colour only sorts the calculated model value into rough ranges. It confirms neither a service's requirements nor protection against phishing, reuse or insecure storage.

Can I use the generated passwords in production systems?

Whether a password fits is determined by the rules and protection needs of the target system. The local random source alone does not make it suitable for every use case.

Which is better: password or passphrase?

Passphrases (e.g. 4–5 random words) are easier to remember and can offer similar entropy to short complex passwords. For machine-stored credentials (password managers) random character strings are optimal.

Tips

Good to know

  • Use a separate password for every service.
  • Store strong passwords in a password manager.
  • More length enlarges the modelled search space, but is not a security guarantee.

Related calculators

More tools