Password Generator
Strong random passwords, generated in your browser
Enter a length (8-64)
Strong random passwords, generated in your browser
Enter a length (8-64)
Most passwords are cracked, not guessed. Attack programs try billions of combinations per second against leaked password databases, and they start with the patterns humans love — names, years, substitutions like "a" → "@". The only reliable defence is length plus genuine randomness, which is exactly what this generator produces.
Choose a length between 8 and 64 characters, tick the character types you want — uppercase, lowercase, digits, symbols — and optionally exclude lookalikes such as I, l, 1, O and 0. Every press of the button draws characters with crypto.getRandomValues(), your browser's cryptographic random number generator, so the result is unpredictable even to someone who knows every option you picked.
The pool is the total number of distinct characters allowed. All four sets gives 94 characters before exclusions, so log₂(94) ≈ 6.55 bits per character — a 16-character password carries about 105 bits. The crack-time estimate assumes an offline attack at 100 billion guesses per second, roughly the speed of a serious GPU rig against a stolen hash file.
| Length | Pool | Entropy | Offline crack time |
|---|---|---|---|
| 8 | 94 | 52 bits | hours–days |
| 12 | 94 | 79 bits | millions of years |
| 16 | 94 | 105 bits | billions of years |
One reassurance about this page: it is a static file with no server and no analytics on the inputs. Generate a password with your network disconnected if you want proof — it works exactly the same.
大多数密码不是被「猜」出来的,而是被「跑」出来的。攻击程序对泄露的密码库每秒可尝试数十亿次组合,而且会优先尝试人类爱用的套路——姓名、年份、"a" 换成 "@" 这类替换。唯一可靠的防线是长度加真随机,这正是本生成器做的事。
选择 8–64 位的长度,勾选想要的字符类型——大写、小写、数字、符号——并可选排除 I、l、1、O、0 这类易混字符。每次点击生成都通过 crypto.getRandomValues()(浏览器内置的加密级随机数发生器)取值,即使别人知道你选的全部选项,也无法预测结果。
字符池是允许出现的全部不同字符数。四类全选、未排除易混字符时共 94 个字符,log₂(94) ≈ 6.55 位/字符——16 位密码约携带 105 位熵。破解耗时按离线攻击每秒 1000 亿次估算,大致是对着被拖走的哈希库用高端显卡集群跑的速度。
| 长度 | 字符池 | 熵 | 离线破解耗时 |
|---|---|---|---|
| 8 位 | 94 | 52 位 | 数小时到数天 |
| 12 位 | 94 | 79 位 | 数百万年 |
| 16 位 | 94 | 105 位 | 数十亿年 |
关于本页可以放心的一点:它是纯静态文件,没有服务器、也不会把任何输入发出去。想验证的话,断网生成一个密码试试——一切照常工作。
Length and randomness. Every extra character multiplies the work an attacker must do, and true randomness removes patterns that cracking software exploits. A 16-character random password mixing all four character types has about 100 bits of entropy — far beyond practical offline cracking.
Yes. They are produced locally by crypto.getRandomValues(), the browser's cryptographic random number generator, and never sent anywhere — there is no server involved. The page is a static file you can even disconnect from the network and keep using.
Only if you will type the password by hand from a printed copy, where I/l/1 and O/0 are easy to confuse. When a password manager fills it in automatically, keeping those characters makes the pool larger and each character slightly harder to guess.
Last reviewed: October 5, 2026 · How we calculate · Sources: NIST SP 800-63B
最近复核:2026 年 10 月 5 日 · 我们的计算方法 · 来源:NIST SP 800-63B