One password per service
When one site leaks, a reused password opens every other one. A unique password limits the damage to a single place.
Passwords drawn from your browser's cryptographic random source, with the length and characters you choose. Copy, paste into the sign-up form and save it in your password manager.
Passwords come from your own browser's cryptographic random source (crypto.getRandomValues). Nothing is sent, logged or stored: no server takes part. Close the page and the password exists only where you pasted it.
Entropy counts how many combinations exist: 2 to the power of the bits. An 80-bit password has about 10^24 possibilities. The math only holds for truly random passwords like the ones generated here: a password you make up with the same letters is far more predictable, and the meter cannot see that. The time estimate assumes an offline attack against a fast hash. A site that rate-limits attempts holds out much longer; a password leaked in plain text falls instantly, however strong.
Drag the length control and tick the sets. If a site rejects symbols, untick them and raise the length to make up for it.
Each click generates a fresh password. The meter shows the bits of entropy and how long a brute-force attack would take.
Copy, paste into the sign-up form and save it in your password manager. Need several? Generate 5, 10 or 20 at once.
When one site leaks, a reused password opens every other one. A unique password limits the damage to a single place.
Nobody memorizes 16 random characters, and nobody has to. A password manager stores, fills in and warns you about breaches.
Even with the right password, an attacker stops at the second factor. Prefer an authenticator app over SMS.
For important accounts such as email, banking and your hosting panel, 16 characters with every set enabled exceed 100 bits.
A long, random and unique one. Long: 12 characters at minimum, 16 or more for important accounts. Random: generated by a computer, not by you, because names, dates and dictionary words are the first guesses in any attack. Unique: each service gets its own, so one breach does not bring down the rest.
With letters, numbers and symbols, 12 characters already exceed 75 bits of entropy and 16 exceed 100 bits, which makes brute force impractical. If a site does not accept symbols, make up for it with length: 20 characters of letters and numbers only equal about 119 bits.
No. Generation uses your browser's crypto.getRandomValues function and happens entirely on your device. No server is involved in that step, nothing is logged and no history is kept. Close the tab and the password no longer exists here.
Entropy measures how many different combinations the password could have: each bit doubles the number of possibilities. A 10-character password from a set of 94 has 10 x log2(94), about 65 bits. Bits are the standard unit because they let you compare passwords of different lengths and sets with a single ruler.
No. Breaches happen all the time, and the first thing an attacker does with a leaked password is try it on your email, social networks and bank. Generate a different password for each service and let your password manager remember it for you.
You will not, and you do not have to. Use a password manager: the browser's own, the phone's system one or a dedicated app. It stores, fills in and syncs across devices. The only password to memorize is the manager's, which can be a long passphrase.
For when the password will be typed by hand or read over the phone: capital I, lowercase l and the digit 1 get confused, as do O, o and 0. The option removes those characters from the draw. The set gets slightly smaller, so add one or two characters of length to compensate.
Comece em 5 minutos. Migração gratuita (no plano semestral), suporte 24/7 em português e garantia de reembolso de 7 dias (30 dias em hospedagem de sites e WordPress).
Usamos cookies para analisar o tráfego, melhorar sua experiência e personalizar conteúdo. Você decide o que aceitar — consulte a Política de Cookies.
Escolha quais categorias você permite. Os cookies necessários são essenciais para o site funcionar e não podem ser desativados.
Essenciais para navegação, segurança e funcionamento básico do site. Não rastreiam você.
Ajudam a entender, de forma anônima, como os visitantes usam o site (Google Analytics).
Permitem medir a eficácia de campanhas e exibir anúncios relevantes (Meta Pixel).