Password Tools
Check how strong a password really is, generate one properly, build a passphrase you can actually remember, and find out whether a password has already appeared in a public breach. Everything runs in your browser — no password you type here is ever sent to us.
Your password is hashed in this browser. Only the first five characters of that hash leave the page, and the matching is done here — the service cannot tell which password you asked about. The mechanism is explained below.
Key takeaway: length beats complexity. Adding one character to a random password
multiplies the work an attacker must do by the size of the alphabet; swapping an a for an
@ multiplies it by almost nothing, because every cracking tool tries that substitution
automatically.
Why most strength meters lie to you
The usual meter counts which character types you used and how long the password is, then multiplies.
By that arithmetic Password123! looks excellent — twelve characters, four character classes,
around 78 bits. In reality it is one of the first few thousand guesses any cracking tool makes, because
attackers do not brute-force character by character. They start with leaked password lists, then apply
rules: capitalise the first letter, append a year, swap a for @, add an
exclamation mark.
The checker here estimates both. It calculates the same theoretical ceiling, then looks for the patterns those rules exploit — a dictionary word with digits bolted on, a year, a keyboard run, a repeated character — and tells you when the realistic figure is far below the flattering one. When the two differ by a wide margin, that gap is the finding.
What the entropy number means
Bits of entropy are a doubling count: each extra bit doubles the number of guesses required. Forty bits is a trillion guesses, which sounds enormous and is not — a single modern GPU can make that many attempts against a poorly hashed password in seconds. Sixty bits is a reasonable floor for an account that matters. Eighty and above is comfortable for a very long time.
The two crack-time figures reflect the difference that the site makes, not you. A service that stores passwords with a slow algorithm like bcrypt or Argon2 limits attackers to thousands of guesses per second. One that used a fast hash — or no hash at all — lets them make hundreds of billions. You cannot control which you are dealing with, which is the real argument for a long password and a different one everywhere.
Generated passwords, and why the old generator here was wrong
A generator is only as good as its source of randomness. The previous version of this page offered a
“memorable” mode built with Math.random() — a function designed to be fast and evenly
distributed, not unpredictable. Its internal state can be recovered from a handful of outputs. That mode also
drew from a 47-word list in a fixed pattern, giving under 14 million possible results, roughly 24 bits. The
meter then displayed around 91 bits for those passwords, because it was measuring the characters rather than
the process that produced them.
Everything generated here now comes from crypto.getRandomValues, the browser’s
cryptographic random source, using rejection sampling so every character is equally likely rather than
slightly biased toward the start of the alphabet. The entropy shown for a generated password is exact,
because the generation process is known: length multiplied by the log of the pool size.
Passphrases
Several random words are easier to remember than a random string and can be just as hard to guess, provided the words are chosen randomly — not by you. The strength comes from the size of the list and the number of picks, so this tool states both: the list holds 7,776 words, which is 12.9 bits each.
| Words | Entropy | Reasonable for |
|---|---|---|
| 4 | ~52 bits | Low-stakes accounts only |
| 5 | ~65 bits | Everyday accounts |
| 6 | ~78 bits | A sensible default |
| 7–8 | ~90–103 bits | Master passwords, encryption keys |
The words come from the EFF Large Wordlist by the Electronic Frontier Foundation (used under CC BY 3.0 US) — the same 7,776-word list designed for rolling five dice, so a passphrase from this page is exactly as strong as one you would roll by hand. Every word is picked with your browser’s cryptographic random number generator.
How the breach check stays private
It uses a technique called k-anonymity, and it is worth understanding because it is the reason this is safe to use:
Your password is hashed with SHA-1 in your browser. Only the first five characters of that hash are sent to the breach database. The service answers with every hash suffix it holds that starts with those five characters — typically several hundred — and your browser checks the list locally. The service learns that someone asked about one of roughly 800 possible hashes, and nothing more. Your password never leaves the page, and neither does its complete hash.
A “found” result means that exact password appears in breach data, so it is in the lists attackers try first — change it everywhere. A “not found” result means only that: it is not evidence the password is strong. A password you invented yesterday will not be in any breach and may still be guessable in seconds.
Nobody can remember thirty unique 20-character passwords, and reuse is what turns one company’s breach into a problem with your accounts. A password manager means you remember one strong passphrase and it handles the rest — generating, storing and filling. Pair it with two-factor authentication on email and banking, which blocks an attacker even when they do have the password.
Bitdefender Secure the rest of your setupAffiliate link. We do not rank by commission, and a free open-source manager is a perfectly good answer too — the important part is using one at all.
What these tools cannot tell you
Whether a specific account is safe. Strength is one factor. Phishing, malware on your own machine and a company storing passwords badly all defeat a strong password without touching it.
Whether a password has been stolen recently. The breach database covers what has been collected and published. A breach nobody knows about yet is not in it.
The exact time to crack. The figures assume a particular attack against a particular hash. They exist to convey scale — instant, hours, centuries — not to be quoted precisely.
Frequently asked questions
Is it safe to type my real password here?
The strength checker and both generators do not make any network request at all — you can disconnect and they still work. The breach check makes one request containing five characters of a hash. That said, the cautious habit is to never type a live password into any website, and you lose nothing by testing a close variant instead.
Should I change passwords regularly?
No. Forced rotation makes people pick weaker, patterned passwords — Spring2026! becomes
Summer2026!. Modern guidance from NIST and the UK’s NCSC is to use long unique passwords and
change them when there is a reason to: a breach, a shared device, a suspicion.
Are symbols really necessary?
They help, but far less than length. Adding four characters to a lower-case password does more for you than sprinkling punctuation through a short one. Use them where a site demands them and do not treat them as the thing that makes a password strong.
What about the security questions?
Treat them as extra passwords, not as questions. Your mother’s maiden name and your first school are findable, and answers get breached along with passwords. Generate a random string and store it in your manager as the answer.
Why does the checker rate my long password badly?
Almost always because it is built from a recognisable word plus additions, or contains a sequence or a year. Length helps only when the characters are unpredictable — thirty characters of song lyric is far weaker than twelve random ones.
Related reading
- Securing your home network
- How ransomware gets in
- What someone can do with your IP
- What SSL/TLS actually protects
- Is this site a scam?
- How packet capture works
- Remove yourself from data brokers
- Is your webcam spying on you?