Create a strong random password, a memorable passphrase or a PIN, generated on your device and never sent anywhere.
Generated entirely in your browser using its cryptographic random source. Nothing is transmitted or stored.
People are bad at randomness. Asked to make up a password, most of us reach for a word we know, a year that matters, and a symbol at the end, which is exactly what cracking software is built to guess. A generator removes the human pattern completely.
This one makes three kinds of secret. A passphrase is several random words, easy to type and surprisingly strong. A random password is a string of mixed characters, ideal when a password manager remembers it for you. A PIN is for devices and cards that lock after a few wrong attempts. Pick the one that matches how the secret will be used.
Your password manager master password and your main email account are the two secrets that protect everything else, and neither can be filled in by a manager when you first unlock it. That is the case a passphrase is built for: six random words are strong enough and you can actually type them on a phone.
For every other account, let the password manager generate and remember a long random string. You never need to see it, so there is no reason to make it memorable, and uniqueness per site means one breach cannot spread.
Security questions are a hidden weak point. Answers like your first school or your mother's maiden name are often findable online or in breach data. Use the generator to make a random answer, store it in your password manager, and treat it like a second password.
Wi-Fi passwords, disk encryption and backup encryption keys are also good uses for a long passphrase, because they are attacked offline where no lockout slows the attacker down.
For secrets you must remember and type, yes. Five or six random words are easier to type accurately than a jumble of symbols and are just as hard to crack. For accounts a password manager fills in, a long random password is fine and slightly stronger per character.
Five words from the large list is a strong default for important accounts. Use six or seven for a password manager master password or anything that protects encrypted data. Four words is the minimum and only suitable where login attempts are limited.
Only ones that generate in your browser and send nothing. This page does exactly that, which you can confirm by disconnecting from the internet after the page loads: the generator keeps working. Avoid any generator that makes the password on a server.
Diceware is a method for building passphrases by rolling dice to pick words from a numbered list. The Electronic Frontier Foundation published improved lists in 2016 that avoid confusing, offensive and hard to spell words. This tool picks from those lists using a digital random source instead of dice.
At least 16 random characters for accounts a manager fills in, or at least five random words for a passphrase. Current guidance from NIST emphasises length over complexity rules and advises against forced regular changes unless a password has been exposed.
Yes. Reuse is how one breach turns into many hacked accounts. The only practical way to do it is a password manager, which remembers them all behind one strong passphrase.