Length beats complexity
The rules most of us learned - one capital, one number, one symbol - optimise for the wrong thing. They make passwords hard for humans to remember while adding very little difficulty for a machine, because people satisfy them predictably: the capital goes first, the number and exclamation mark go last.
Length is what actually costs an attacker time, because each additional character multiplies the search space. A sixteen-character password drawn from a decent alphabet is far stronger than an eight-character one contorted to satisfy four rules, and current guidance from NIST reflects exactly this shift.
When a passphrase is the better answer
A passphrase is several random words joined together. Four or five randomly chosen words give you strength comparable to a long random string, while remaining something a human can hold in their head and type on a phone keyboard without swearing.
The word randomly is doing the work. Words you chose yourself are not random - they cluster around your interests and are dramatically weaker than they appear. A passphrase is only strong when a machine picked the words.
Use a passphrase where you must type it from memory: a device login, a disk encryption key, a password manager master password. Use a long random string everywhere the manager types for you.
Why generating in the browser matters
A password generated on a server is a password that existed, however briefly, on someone else machine and possibly in a log. This one is generated by the Web Crypto API in your own browser, from a source designed to be unpredictable. Nothing is transmitted and nothing is stored.
The remaining advice is unglamorous and more important than the generator: use a different password on every site, keep them in a password manager, and turn on two-factor authentication wherever it is offered. A unique password limits one breach to one account.
Frequently asked questions
- Are these passwords sent over the internet?
- No. Generation happens in your browser using the Web Crypto API. Nothing is transmitted, logged or stored anywhere.
- How long should a password be?
- Sixteen characters or more for anything a password manager will type for you. Length contributes far more strength than character-class rules do.
- Is a passphrase safer than a random password?
- A passphrase of four or five randomly chosen words is comparably strong and far easier to type from memory. The words must be machine-chosen; self-selected words are much weaker than they look.
- Do I still need special characters?
- Only where a site demands them. A longer password without symbols generally beats a short one with them, though many sites still enforce the old rules.
- Can the same password be generated twice?
- It is theoretically possible and practically irrelevant at any reasonable length - the search space is far too large for a repeat to occur.