What is a password and why strength matters
A password is a string of characters used to verify your identity and protect an account from unauthorized access. In today's internet age, almost everyone has passwords for email, banking, social media, and work accounts. Because passwords are the first line of defense for your digital life, understanding how to construct a strong password is essential.
Password strength is a measure of how effectively a password resists being guessed or cracked by a brute-force attack. Strength is driven by three factors:
- Length — each additional character multiplies the number of possible combinations
- Complexity — a wider variety of character types (letters, numbers, symbols) increases the pool
- Unpredictability — random passwords are far stronger than words, names, or dates that attackers can guess or look up
How to create a secure password
A secure password follows rules designed to maximize its resistance to attack:
- Include lowercase letters
[a-z] - Include uppercase letters
[A-Z] - Include numbers
[0-9] - Include symbols
[!@#$%^&*()...] - Exclude personal information (names, birthdays, pet names)
- Exclude words found on password blacklists (password, 123456, qwerty)
- Exclude company or institution names and their abbreviations
- Exclude common formats like calendar dates, phone numbers, and license plates
The longer the password and the larger the variety of character types, the more secure it is. Using a random password generator is the most reliable way to follow all of these rules at once.
Password entropy explained
Password entropy measures the unpredictability of a password in bits. The higher the entropy, the harder the password is to guess. In a brute-force search, a password with 100 bits of entropy would require up to 2¹⁰⁰ attempts to exhaust every possibility — on average, about half that many guesses are needed before the correct one is found.
The entropy formula is:
Where:
- H is the entropy in bits
- L is the password length
- N is the number of possible characters in the pool
For example, a 16-character password using all 94 printable ASCII characters has an entropy of 16 × log₂(94) ≈ 104.9 bits.
Entropy and strength levels
| Entropy (bits) | Strength | Use case |
|---|---|---|
| Under 28 | Very Weak | Not recommended for any account |
| 28–35 | Weak | Low-security only |
| 36–59 | Fair | Casual, non-sensitive accounts |
| 60–127 | Strong | Most online accounts and email |
| 128+ | Very Strong | Banking, password vaults, encryption keys |
How to generate a random password step by step
- Choose a length — start at 16 characters or more for important accounts.
- Enable all character types — lowercase, uppercase, numbers, and symbols to maximize the pool.
- Decide on ambiguous characters — if you will type the password by hand, enable "Exclude ambiguous characters" to remove look-alikes such as
I,l,1,O, and0. - Generate — the tool creates the password locally in your browser using a cryptographically secure random number source.
- Check the strength and entropy — aim for at least 60 bits, ideally 100+ for sensitive accounts.
- Copy and store — paste the password into your account, then save it in a password manager rather than a text file.
What are ambiguous characters and when to exclude them
Ambiguous characters are characters that look alike and are easy to confuse when reading or typing a password. Common examples include:
- Uppercase
I, lowercasel, and the number1 - Uppercase
Oand the number0 - Uppercase
Oand lowercaseo - The number
5and uppercaseS - The number
8and uppercaseB
Excluding these characters is especially useful when you generate a password you must read from a screen and type into another device. Note that removing characters shrinks the pool slightly, which lowers entropy — so only use this option when readability matters more than maximum strength.
How to protect your password
Creating a strong password is only half the battle. Protecting it is just as important:
- Don't share your password — ideally, you should be the only person who knows it. Even trusted friends may be less careful about safeguarding it.
- Don't reuse passwords across accounts — a breach on one site should not expose every account you own. A password manager makes it easy to use a unique password for each account.
- Change passwords periodically — regular changes limit the window of exposure if a password is quietly compromised.
- Never save passwords on public devices — avoid saving credentials in browsers on shared or public computers.
- Use two-factor authentication — even if your password is stolen, a second verification step blocks most attackers.
- Store passwords in a password manager — avoid sticky notes, Word documents, or phone notes labeled "passwords," which are easy targets if a device is lost or stolen.
Common password mistakes to avoid
- Using personal information such as names, birthdays, or pet names
- Choosing common passwords like
password,123456, orqwerty - Reusing the same password across multiple websites
- Saving passwords in plain text files on your desktop or phone
- Sharing passwords with coworkers or friends
- Ignoring password breaches — change any password that may have been exposed in a known data breach
Random vs. memorable passwords
Random passwords generated by a tool are the most secure because they have maximum entropy and contain no guessable patterns. The trade-off is that they are impossible to memorize, which is why a password manager is recommended.
If you must memorize a password, consider a passphrase — a sequence of four or more unrelated words, such as correct-horse-battery-staple. Passphrases are long, easier to remember, and can still achieve high entropy when the words are truly random.
Frequently asked questions
Is a generated password safe to use online? Yes. This generator creates passwords entirely in your browser using a cryptographically secure random source. The password is never sent across the internet.
How long should my password be? For most accounts, 16 characters or more is recommended. For highly sensitive accounts like banking or password manager vaults, use 20 characters or more.
What is a good password entropy? Aim for at least 60 bits for everyday accounts and 100 bits or more for sensitive accounts. 128 bits is considered extremely secure against any realistic brute-force attack.