A password generator for the passwords a manager will not hold

Password managers bundle a generator because the generator is the easy part, and if the password you are about to create is going into a manager, use the one built into it - fewer steps, and it lands where it belongs. This page is for the passwords that are not going into one.

Open the Password Generator →

the LastPass generator and Softland, side by side

 the LastPass generatorSoftland
Where randomness comes fromThe extension or the siteYour browser cryptographic random source
PassphrasesOfferedOffered, as a first-class option
Storing the resultStraight into the vaultNowhere - it exists in the page and your clipboard
Account or extensionExpected, for the part that mattersNeither
Sharing a credential with someoneSupportedNot here - see the paste tool, with an expiry

The generator is not the hard part

Producing an unguessable string is a solved problem that takes one line of code. The hard problem is everything after: remembering it, storing it somewhere both safe and reachable, not reusing it, and getting it to the other person when a credential has to be shared. A password manager exists to solve those, and a standalone generator solves none of them.

So the honest recommendation is that if you are creating a login you will use repeatedly, you want a manager, and its generator is right there. What a manager is a clumsy fit for is the other category: a wifi key going on a card by the door, a database password destined for a secrets store, a one-off credential you are handing to a contractor, a seed for something that is not a login at all.

Length beats character classes, and it is not close

Every character you add multiplies the search space. Every mandated symbol adds roughly the same entropy as one more character while making the password harder to type and more likely to be written down. This is why the requirement to include an uppercase letter, a digit and a symbol produces Password1! on millions of accounts - the rule was satisfied and nothing was achieved.

Current guidance from the standards bodies has moved accordingly: favour length, drop composition rules, stop forcing periodic rotation, and check against lists of known-breached passwords instead. A long random string or a multi-word passphrase beats a short cryptic one every time, and is far likelier to be entered correctly on a phone.

When a passphrase is the better answer

Several random words are strong through length rather than through obscurity, and the crucial word is random - words you chose yourself are not, because human word choice is predictable in exactly the ways an attacker models. A generated four or five word phrase is easy to read aloud over a phone, easy to type on a television remote, and hard to mistranscribe.

That makes it the right shape for credentials that humans have to move around by hand: a wifi password, a device unlock code, a disk encryption phrase, the master password protecting everything else. Use a random string for anything a machine will handle, and a passphrase for anything a person will.

When the LastPass generator is the better choice

  • The password is for an account you will log into regularly - generate it inside the manager that will store it, not here.
  • You need the credential shared with a team, with access that can be revoked later.
  • You want autofill, breach alerts and a record of where each credential is used, which is the actual value of a manager.

Frequently asked questions

Are these passwords sent over the internet?
No. They are generated by your browser cryptographic random source and never transmitted. That is what makes it safe to use one - a generated password that was sent anywhere is not a secret.
How long should a password be?
Longer than the rules demand. Length contributes far more than character variety, so sixteen random characters or four random words beats eight cryptic ones. For anything protecting other credentials, go longer still.
Is a passphrase safer than a random string?
At equal strength they are equivalent, and the passphrase is much easier for a person to handle. Use one wherever a human has to type, read out or remember the credential; use a random string where a machine will hold it.
Can the same password be generated twice?
Theoretically, in the way that two random numbers can coincide. With a cryptographic random source and a sensible length the probability is small enough to ignore, and there is no shared state that could cause it deliberately.

Try it yourself

Strong random passwords and passphrases.

Open the Password Generator

the LastPass generator is a trademark of its respective owner. Softland is not affiliated with, endorsed by or sponsored by the LastPass generator. This comparison reflects how each product works rather than what either costs, because pricing and plan limits change; check the LastPass generator’s own site for its current terms.