How to Generate a Password That's Actually Strong
Password advice is full of half-right folk wisdom — mix in symbols, avoid dictionary words, change it every 90 days. Some of it helps, some of it doesn't, and the single biggest factor is usually left out of the conversation entirely: length.
Generate one in your browser (free, instant)
The Password Generator on keptlocal creates a random password using your browser's cryptographic random number generator, the moment the page loads.
- Set the length with the slider — 16 characters minimum for anything that matters, 20+ for high-value accounts.
- Choose which character sets to include: uppercase, lowercase, numbers, symbols.
- Click Generate password as many times as you like.
- Click Copy and paste it into your password manager.
Entropy, in plain terms
Password strength is measured in bits of entropy — roughly, how many yes/no guesses an attacker would need in the worst case to find your password by brute force. Every extra character multiplies the number of possible passwords by the size of your character set; every bit of entropy doubles the search space. A 16-character password drawn from the full 94-character printable ASCII set has around 105 bits of entropy — a number large enough that brute-forcing it, even with dedicated cracking hardware running for the age of the universe, still wouldn't reliably succeed.
The practical takeaway: going from 8 characters to 16 characters matters enormously more than going from three character types to four. If you have to choose between a longer password and a "more complex" shorter one, choose length.
Why "clever" substitutions don't help
Swapping letters for look-alike numbers (p@ssw0rd), appending a year, or using a keyboard walk (qwerty123) all feel less guessable to a human, but password-cracking tools are built with exactly these patterns as their first line of attack — they include massive dictionaries of common words, names, and substitution patterns, and try them (with variations) before falling back to brute force. A password with no underlying pattern — because it's genuinely random — has nothing for a pattern-based attack to exploit. This is the entire reason to use a generator instead of inventing a password yourself: human-invented "randomness" is far more predictable than it feels.
Where the randomness actually comes from
This tool uses window.crypto.getRandomValues(), part of the Web Cryptography API — it draws from the operating system's cryptographically secure entropy source, the same category of randomness used by disk encryption and secure messaging apps. This is a meaningfully different guarantee than Math.random(), a pseudorandom generator built for speed and statistical spread (fine for a dice-roll animation, wrong for a password) whose output sequence is, in principle, predictable if an attacker can infer the generator's internal state.
After generating: where it goes
A strong password stored badly is still a weak security posture. The generated password should go straight into a password manager — Bitwarden (free, open source), 1Password, or your browser's built-in manager — not a sticky note, a plain-text file, or a note-taking app without encryption. A password manager also makes using a unique password per account practical, which matters: reused passwords mean one breach compromises every account sharing that password.
Generate a strong password now with keptlocal's free Password Generator — no upload, no signup.
Frequently asked questions
Is length really more important than using symbols?
Why shouldn't I use Math.random() for a password generator?
Is a memorable password (a phrase, a pattern) ever as strong as a random one?
How often should I change my passwords?
Should every account really have a different password?
Generate strong, random passwords — free, in your browser.
No upload. No signup. Runs in your browser.