keptlocal
· 4 min read · Utility

How to Generate a Password That's Actually Strong

HP
Hitendra Patel
Founder, keptlocal · Senior Technical Lead, Healthcare IT

Password advice is full of half-right folk wisdom — mix in symbols, avoid dictionary words, change it every 90 days. Some of it helps, some of it doesn't, and the single biggest factor is usually left out of the conversation entirely: length.

Generate one in your browser (free, instant)

The Password Generator on keptlocal creates a random password using your browser's cryptographic random number generator, the moment the page loads.

  1. Set the length with the slider — 16 characters minimum for anything that matters, 20+ for high-value accounts.
  2. Choose which character sets to include: uppercase, lowercase, numbers, symbols.
  3. Click Generate password as many times as you like.
  4. Click Copy and paste it into your password manager.

Entropy, in plain terms

Password strength is measured in bits of entropy — roughly, how many yes/no guesses an attacker would need in the worst case to find your password by brute force. Every extra character multiplies the number of possible passwords by the size of your character set; every bit of entropy doubles the search space. A 16-character password drawn from the full 94-character printable ASCII set has around 105 bits of entropy — a number large enough that brute-forcing it, even with dedicated cracking hardware running for the age of the universe, still wouldn't reliably succeed.

The practical takeaway: going from 8 characters to 16 characters matters enormously more than going from three character types to four. If you have to choose between a longer password and a "more complex" shorter one, choose length.

Why "clever" substitutions don't help

Swapping letters for look-alike numbers (p@ssw0rd), appending a year, or using a keyboard walk (qwerty123) all feel less guessable to a human, but password-cracking tools are built with exactly these patterns as their first line of attack — they include massive dictionaries of common words, names, and substitution patterns, and try them (with variations) before falling back to brute force. A password with no underlying pattern — because it's genuinely random — has nothing for a pattern-based attack to exploit. This is the entire reason to use a generator instead of inventing a password yourself: human-invented "randomness" is far more predictable than it feels.

Where the randomness actually comes from

This tool uses window.crypto.getRandomValues(), part of the Web Cryptography API — it draws from the operating system's cryptographically secure entropy source, the same category of randomness used by disk encryption and secure messaging apps. This is a meaningfully different guarantee than Math.random(), a pseudorandom generator built for speed and statistical spread (fine for a dice-roll animation, wrong for a password) whose output sequence is, in principle, predictable if an attacker can infer the generator's internal state.

After generating: where it goes

A strong password stored badly is still a weak security posture. The generated password should go straight into a password manager — Bitwarden (free, open source), 1Password, or your browser's built-in manager — not a sticky note, a plain-text file, or a note-taking app without encryption. A password manager also makes using a unique password per account practical, which matters: reused passwords mean one breach compromises every account sharing that password.

Generate a strong password now with keptlocal's free Password Generator — no upload, no signup.

Frequently asked questions

Is length really more important than using symbols?
For a given character-set choice, yes — each additional character multiplies the number of possible passwords, while adding one more character type (say, symbols on top of letters and numbers) only adds a modest multiplier. A longer password with fewer character types often beats a shorter one with every type included.
Why shouldn't I use Math.random() for a password generator?
Math.random() is a pseudorandom number generator designed for speed and statistical distribution in things like games and simulations — it is not cryptographically secure and its output can, in principle, be predicted. window.crypto.getRandomValues() draws from the operating system's cryptographic entropy source, the same standard used by encryption software, and is the only appropriate choice for anything security-related.
Is a memorable password (a phrase, a pattern) ever as strong as a random one?
A truly random long passphrase (several unrelated dictionary words, like a Diceware passphrase) can rival a random character string in entropy while being easier to remember. A password based on a predictable pattern — a word plus a number, a keyboard walk, a substitution like "p@ssw0rd" — is much weaker than it looks, because password-cracking tools are built specifically to try these patterns first.
How often should I change my passwords?
Current security guidance (NIST, among others) has moved away from mandatory periodic password changes for accounts with strong, unique passwords and no evidence of compromise — frequent forced changes tend to push people toward weaker, more predictable passwords. Change a password immediately if the service reports a breach; otherwise, a strong unique password generated once per account, stored in a password manager, doesn't need routine rotation.
Should every account really have a different password?
Yes — this matters more than almost any other password habit. If one service is breached and its password database cracked, every other account using that same password is immediately at risk. A password manager makes unique passwords for every account practical without having to memorize them.
Free browser tool
Password Generator

Generate strong, random passwords — free, in your browser.

No upload. No signup. Runs in your browser.

Use Password Generator