How this is worked out
Every character and every word is chosen with crypto.getRandomValues, the browser's cryptographic random source. Math.random is not used anywhere — it is a fast non-cryptographic generator whose future output can often be predicted from a handful of past values, and for a password that is fatal.
There is a second, subtler trap that most generators fall into. Taking random % 62 to pick from a 62-character alphabet biases the result toward low values, because 256 is not a multiple of 62 — the first eight characters come up about 0.4% more often than the rest. Small, invisible, and it erodes exactly the property you are generating for. This generator rejects and redraws any value that would land in the biased tail.
Strength is entropy, measured in bits:
bits = length × log₂(pool size)
A 20-character password from an 87-character pool is 20 × log₂(87) ≈ 128.9 bits. For a passphrase it is the number of words times the bits per word, where a 709-word list gives about 9.5 bits each.
Time to crack is then the search space divided by the guess rate, halved because on average you find it halfway through. The guess rate is the assumption that matters, so it is a visible control rather than a hidden constant.
A worked example
- 20 characters, all four sets
- 87-character pool
- Entropy
- 128.9 bits
- Online, rate limited
- longer than the universe has existed
- Offline, bcrypt
- longer than the universe has existed
- Offline, fast hash
- longer than the universe has existed
- A 6-word passphrase instead
- 56.8 bits
- Same phrase, offline fast hash
- about a week
- A 12-character password
- 77.3 bits — about 760,000 years
A strength meter that says "strong" is not telling you anything
Strong against whom, using what, for how long? The five-segment coloured bar on most sign-up forms answers none of those, and it is frequently scoring the wrong thing entirely — rewarding a capital letter and a punctuation mark on a short dictionary word while marking a long random string down for having no symbols.
Time to crack under a stated attack model is a real answer, because it forces the assumption into the open. The same password is uncrackable against a rate-limited login and gone in an afternoon against a leaked fast-hashed database, and the difference is entirely about the attacker, not the password.
This page defaults to the harsh case — an offline attack on a database hashed with something never designed for passwords — because that is the case that keeps happening. If your password is strong under that assumption, it is strong.
Entropy measures how it was made, not how it looks
This is the point almost every piece of password advice gets wrong. "Tr0ub4dor&3" looks random and is worth far fewer bits than it appears: it is one dictionary word with predictable substitutions and a couple of additions, and a cracking tool built around exactly those rules finds it quickly.
A password's strength is a property of the process that generated it. Twenty characters drawn uniformly at random from 87 possibilities is 128.9 bits whether the result looks like line noise or spells something. Twenty characters you chose yourself, believing them unpredictable, is worth much less — because you are not a random source and the patterns you reach for are the patterns everyone reaches for.
That is also why "correct horse battery staple" is strong when a machine picks the four words and much weaker when a person does. The strength was in the dice, not the words.
Passphrases, and the honest arithmetic
A passphrase trades length for memorability, and the trade is real — but the strength is entirely in the list size and the number of words, not in how random the phrase feels to read.
The word list here is 709 short, unambiguous English words, which gives about 9.5 bits per word. Diceware's standard list has 7,776 words and gives 12.9. That difference is why a passphrase from this list needs roughly a third more words for the same strength, and it is why the default here is six rather than the four that circulates in the famous comic.
Six words from this list is 56.8 bits — enough to be well beyond an online attack and genuinely not enough against a fast offline one. Eight words is 75.8. If you want a passphrase you can memorise and still be comfortable about a database leak, eight is the number, and the table on this page shows why.
Length beats complexity, and uniqueness beats both
Adding a symbol to a 12-character password adds about 6 bits. Adding four more characters adds about 26. Length is simply the more efficient lever, which is why forced-complexity rules produce passwords that are annoying to type and not much harder to crack.
Past about 80 bits the password stops being the weak point. Nothing realistic cracks it, and the actual risks become reuse, phishing and account recovery flows — none of which a longer password helps with at all.
So the genuinely useful advice is short: use a password manager, let it generate something long and unique for every account, and put your effort into the handful of passwords you must memorise (the manager's own, and your device login) plus turning on two-factor authentication where it is offered. A unique 16-character password on every site beats a magnificent 40-character one used on three.
Assumptions and sources
- Random source
- crypto.getRandomValues, the Web Crypto API's cryptographically secure generator. Math.random is not used anywhere in this tool.
- Modulo bias
- Values landing outside the largest exact multiple of the range are rejected and redrawn, so every character is equally likely.
- Entropy
- bits = length × log₂(pool size) for passwords; words × log₂(list size) for passphrases. Word list: 709 entries, about 9.5 bits each.
- Guess rates
- Approximate orders of magnitude: 100/sec rate-limited online, 10⁵/sec against bcrypt, 10¹¹/sec against a fast hash on commodity GPUs. Hardware improves; treat these as indicative.