How to use the password generator
- Choose Random characters or Passphrase (words).
- For random characters, set the length (8 to 128) and tick the character types you want. Edit the symbols list if a site only allows some.
- Tick Exclude look-alike characters to avoid I, l, 1, |, O, 0 and o. Keep Include at least one of each selected type on for sites with composition rules.
- For a passphrase, choose the number of words, a separator, capital letters and an optional number.
- Choose how many to generate, press Generate, then Copy the one you want. Store it in a password manager.
Formula
Random characters: entropy (bits) = length x log2(pool size)
Passphrase: entropy (bits) = words x log2(2,024) + log2(100) if a number is added
Strength bands: under 40 weak, 40 to 59 fair, 60 to 79 good, 80 to 99 strong, 100 and up very strong
Entropy measures how many equally likely possibilities an attacker would have to search. Each added bit doubles the search. The estimate assumes the secret was generated at random, as it is here.
Worked examples
A 16 character password using lowercase, uppercase, digits and the 24 default symbols draws from a pool of 26 + 26 + 10 + 24 = 86 characters. That gives 16 x log2(86), which is about 102.8 bits. If you also exclude look-alikes the pool is 80 characters and the estimate is about 101.2 bits.
A 5 word passphrase from the 2,024 word list gives 5 x log2(2,024), which is about 54.9 bits. Adding a 0 to 99 number adds log2(100), about 6.6 bits. Eight words give about 87.9 bits.
How the passwords are made
Every character is chosen with the secure random generator in your browser, using rejection sampling so no character is even slightly more likely than another. When "at least one of each" is on, one character from each selected type is drawn first, the rest are drawn from the whole pool, and the lot is shuffled with an unbiased shuffle. That rule removes a tiny fraction of possibilities, so the true entropy is marginally lower than the simple estimate. For realistic lengths the difference is negligible.
The passphrase word list was written for SumPanda and contains 2,024 common English words of 3 to 10 letters, so each word adds about 11 bits. Passphrases are easier to type and remember than random characters of the same strength, which makes them a good choice for a password manager master password or a device login you must type often.
Reading the entropy estimate
More bits is better, and length matters most. Current NIST guidance emphasizes length over forced complexity rules, and discourages reusing passwords. The strength label is only a guide to the estimate, not a promise that a password cannot be guessed. The real risk usually lies elsewhere: a password reused on several sites, a phishing page, malware on your device or a breach of the service itself. Use a different password for every account and turn on two-step verification where it is offered.
Online services normally limit guessing attempts, while stolen password databases can be attacked offline at very high speed, which is why tools suggest at least 60 to 80 bits for important accounts. Treat that as a rule of thumb rather than a fixed standard.
Privacy
Passwords are created in your browser and are never stored, logged or sent anywhere. They disappear when you close or reload the page, so copy the one you need into your password manager right away.
Assumptions and limits
- The entropy figure assumes the whole secret was produced by this generator. A password you change by hand has less than the estimate.
- Some websites limit length or allowed symbols. Edit the symbol list or length to match.
- Look-alike exclusion removes I, l, 1, |, O, 0 and o, which slightly reduces the pool and the entropy.
- Passphrases from a published word list are as strong as the number of words, even if an attacker knows the list. The list here has 2,024 entries.
- No password is guaranteed safe. Reuse, phishing and breaches are not covered by any entropy figure.
Frequently asked questions
Is a longer password or a more complex one better?
Length usually wins. Each added character multiplies the possibilities by the size of the pool, while adding one symbol type grows the pool only modestly. A long random password or passphrase is both stronger and easier to type.
What is entropy in a password?
It is the base 2 logarithm of the number of equally likely passwords the generator could have produced, so 60 bits means about 1.15 quintillion possibilities. It is a measure of how big the search space is.
Are the passwords saved or visible to SumPanda?
No. They are generated in your browser with its secure random source. Nothing is stored in the page, logged or transmitted, and a reload erases them.
Why exclude look-alike characters?
Characters such as l, 1, I, O and 0 are easy to mix up when reading a password aloud or copying it from paper. Excluding them avoids mistakes at a small cost in strength.
Where should I keep a generated password?
In a reputable password manager, which can also fill it in for you. If you need a random value that is not a password, such as a draw, use the random number generator.