Is it safe to generate passwords online?
Yes, when the generator uses crypto.getRandomValues and runs locally, as this one does. Passwords are never sent, stored or logged; leave or refresh the page and they are gone.
How long should a password be?
At least 15 characters when the password is your only protection, which is the current NIST minimum, and 16 to 20 random characters is a comfortable default. Length adds more strength than complexity rules, and a password manager means you never need to remember it.
Is a 12-character password strong enough?
A random 12-character password from all character sets has about 77 bits of entropy, which is strong. A human-chosen 12-character password is much weaker. For important accounts, use 16 or more random characters.
What is password entropy?
A measure in bits of how many guesses a brute-force attack needs: length × log₂(pool size) for a random password. Each extra bit doubles the guesses, and 80 bits or more is beyond realistic brute force.
Do passwords need symbols and numbers?
They help a little, but length matters more, and current NIST guidance says services should not force composition rules. If a site rejects symbols, untick them and add a few characters.
Why exclude look-alike characters?
Characters like l, 1 and I, or O and 0, are easy to misread when a password is typed from paper or read aloud. Excluding them reduces the pool slightly, so add a character or two to compensate.
Should I change my passwords regularly?
Not on a fixed schedule. NIST guidance says to change a password when there is evidence it has been compromised, not periodically, because forced changes lead to weaker, predictable passwords.
Is a passphrase better than a random password?
A random passphrase of five or six dictionary words is easier to remember and type and is strong enough for a master password. For everything stored in a password manager, a random 16 to 20 character password is shorter for the same strength.
Can I use this for Wi-Fi passwords or API keys?
Yes. Wi-Fi (WPA2 and WPA3 personal) typically accepts 8 to 63 characters, so 20 or more random characters is a good choice. For API keys and secrets, use 32 or more characters.
Where should I keep generated passwords?
In a password manager, with multi-factor authentication or a passkey on accounts that support it. Avoid spreadsheets, notes apps and reusing one password across sites.