Passwords are the one thing you should never reuse. When one site is breached, the same password on your email and your bank account is no longer a private secret, it is a list of targets. Generating a fresh random password for each account removes the link between them entirely.
Why random beats memorable
The problem with a memorable password is that it is, by definition, guessable. Anything following a recognisable pattern, a name plus a year plus a symbol, falls to dictionary and rule-based attacks that run billions of attempts per second against a hashed database. A truly random 16-character string has so many possible combinations that the same attack cannot finish.
What makes randomness strong is length. Every extra character multiplies the number of possible passwords. A 10-character password using all character types has roughly 6 quadrillion possibilities; a 16-character one has about 2000 times as many. Length is the single most effective change anyone can make.
What this tool does and does not do
Everything happens inside your browser using the browser's own cryptographic random number generator, which is designed for exactly this purpose. The generated password is displayed on your screen and nowhere else. It is not transmitted to a server, not stored in a database, not written to a log, and not recoverable later. Once you close or reload the page, it is gone.
Because there is no stored copy, there is also no "forgot password" link for these. Copy the password into your password manager straight away. If you lose it, you reset the account, which is the intended behaviour for a credential you were never meant to remember.
How to use a password manager with this
- Generate the password here.
- Copy it and paste it into your password manager as a new entry with the site name and username.
- Let the manager fill it in from then on, so the long random string never has to be typed by hand.
Every mainstream browser now has a built-in manager that works this way, so no separate paid tool is required. Once the passwords live in a manager, the practical limit on length disappears, and you should use 20 characters or more for the accounts that matter.
Other habits that matter more than the string
- Turn on two-factor authentication wherever it is offered, especially on email, banking and password accounts.
- Never reuse a password that has appeared in a data breach. A breach check on your email address is the quickest way to find out.
- Avoid security questions whose answers are public. A mother's maiden name is not a secret in the way the form assumes.
- Watch for look-alike domains in login emails, and type the address yourself rather than following a link.
Frequently asked questions
How does this password generator create passwords?
It uses the browser cryptographic random number generator rather than the standard Math.random function, so the output is not predictable from previous results. The characters are assembled in your browser and never sent anywhere.
What is the minimum recommended password length?
For most accounts 16 characters is a sensible floor. For email, banking and password manager accounts, 20 or more is better. Length matters more than substituting letters for numbers.
Are the generated passwords stored anywhere?
No. They exist only in the page in front of you and are lost when you close or reload it. That is also why there is no way to recover one later, so save it to a password manager immediately.
Should I use a different password for every account?
Yes. Unique passwords mean a breach at one site cannot be used to attack another. A password manager makes this practical because you only need to remember the master password.