Password maker
Creates a strong password and explains in plain words how good it is. Nothing ever leaves your browser.
Free · runs in your browser · no signupWorried a password you already use has leaked? Check it against known leaks without it leaving your browser.
What the strength line is telling you
The bar and the words underneath are a rough answer to one question: if someone got hold of a stolen file of scrambled passwords and pointed a fast computer at yours, how long would it take to work out?
Anything marked strong or better is fine for normal use. If it says the password is too easy to guess, the fix is almost always the same one: make it longer. Adding characters helps enormously. Swapping an “a” for an “@” barely helps at all, because the people guessing passwords worked out that trick decades ago.
Letters and symbols, or words?
Use the random characters option for anything your password manager will remember for you, which should be nearly every account you have. You never need to type those, so they may as well be long and unmemorable.
Use the word option for the small handful you actually have to type from memory: your computer login, your phone, and the password to the password manager itself. Five or six real words are genuinely hard to break and much easier to remember than a jumble.
Three habits that matter more than any single password
- Use a different password for every site. This is the big one. Reusing a password means one leak, anywhere, puts every account at risk.
- Let something else remember them. Your browser has a password manager built in, and there are good free ones that work everywhere. You remember one strong password and it handles the rest.
- Switch on two-step login where it is offered, especially for email. It means a stolen password on its own is not enough to get in.
You do not need to change passwords on a schedule any more. That advice was quietly dropped years ago, because it mostly pushed people into small predictable changes. Change one when there is a reason to.
Common questions
Is it safe to make a password on a website?
On this page, yes, and here is why you can check it yourself: the password is made by your own browser and never sent to us. Load the page, switch off your internet connection, and it still works perfectly. That would be impossible if anything were being sent anywhere.
What actually makes a password strong?
Length, far more than anything else. Every extra character multiplies the effort needed to guess it, while swapping an "a" for an "@" barely helps. A long, dull password beats a short, clever one every time.
Should I pick the random letters or the words?
Use random characters for anything your password manager will remember for you, which should be almost everything. Use the word version for the handful you have to type from memory, like your computer login, because you can actually remember four or five real words.
How am I supposed to remember all these?
You are not. That is what a password manager is for: you remember one strong password, and it remembers all the others. Your browser has one built in, and there are free standalone ones too.
Do I need to change my passwords regularly?
Not on a schedule. Advice has moved on. Change a password when you have reason to think it has leaked, and otherwise use a long unique one per site and leave it alone.