PRIVATEBYTE
ServersProxiesAgentsStatusNetworkAbout
Sign inDeploy

Tools / Password generator

Your password

 

Very strong · 129 bits · cracked longer than the universe has existed at 100 billion guesses a second

20characters
6words
CharactersLetters and digits are always included.
Separator

Generated on your device. Never sent, never stored.

Choosing a strong password

Attackers do not guess passwords one at a time on a login form. They test billions of guesses a second against stolen password databases. What protects you is randomness and length.

Use a password manager
Let it store a unique random password for every site. Then a breach at one site cannot unlock the others.
Random beats clever
Substitutions like P@ssw0rd are in every cracking list. Characters picked at random by a computer are not.
Length matters most
Each extra random character multiplies the work to crack it. Aim for 16 or more.
Passphrases for what you type
Six random words are as strong as a 12-character random password, and far easier to type on a phone or a server console.
Turn on two-factor
Even a perfect password can be phished. A second factor stops a stolen password being enough.

Questions

Is it safe to generate a password on a website?

This one never leaves your browser. It is created on your device with the browser's cryptographic random generator, and nothing is sent to us or stored. You can load the page, switch off your connection and it still works.

Password or passphrase?

A passphrase of random words is far easier to type and remember at the same strength. Six random words is about as strong as a 12-character password of mixed letters, digits and symbols. Use a passphrase for things you type, and a long random password for things a password manager fills in.

How long should a password be?

At least 16 random characters, or 5 to 6 random words, for anything that matters. Length beats complexity: each extra character multiplies the work an attacker has to do.

What do the bits and crack time mean?

Bits measure how many guesses an attacker needs: every extra bit doubles it. The time assumes a fast offline attack at 100 billion guesses a second against a stolen password database. A website that limits login attempts is far slower to attack than that.

Where do the passphrase words come from?

The EFF large wordlist: 7,776 common English words chosen to be easy to spell and hard to confuse. Each word adds about 12.9 bits.


Every PrivateByte server comes with SSH keys and a firewall you control. See plans.

Wordlist by the EFF, licensed CC BY 3.0.

PRIVATEBYTE

Infrastructure for independent minds.

Service status

Products

Virtual serversProxiesAgentsMigration

Resources

Looking glassSecurityBlogNews

Free tools

What is my IPProxy checkerPort checkerDNS lookupPassword generatorVPS price calculator

Company

AboutContactX / TwitterTelegram
© 2026 PrivateByte Ltd
TermsPrivacyAcceptable useRefundsAbuse & legalSLA

Registered in England & Wales · Company no. 15834803 · 128 City Road, London EC1V 2NX