How to create a strong password
A strong random password for this site’s generator is long enough and drawn from a wide character set. With length 16 and uppercase, lowercase, digits, and symbols enabled (ambiguous characters still included), the charset has 85 symbols and the entropy estimate is about 102.6 bits. The password generator shows that estimate live as you change toggles.
Fake sample (do not use it)
Exactly 16 characters:
Xh4!mK9pQ2$vL7nR
That string is invented for the article. Regenerate in the tool if you need a real secret. Never paste a published sample into an account.
Method
- Open the password generator and stay on the Password tab.
- Set length to 16 (or longer if the site allows).
- Enable upper, lower, digits, and symbols.
- Decide whether to exclude ambiguous characters.
- Regenerate until you are ready to copy into a password manager.
Generation uses your browser’s secure random number generator, not a weak pseudo-random shortcut. Nothing you generate is sent to a server.
Entropy for this model is approximately:
entropy_bits ≈ length × log₂(charset size)
With all four sets on and ambiguous characters still included, charset size is 85, so 16 × log₂(85) ≈ 102.6.
What the toggles change
| Control | Effect |
|---|---|
| Length | Raises or lowers bits roughly in proportion |
| Character sets | Grow or shrink the charset |
| Exclude ambiguous | Removes lookalikes; shrinks the charset |
If a site rejects symbols, turn symbols off and add length instead when the site allows longer passwords. If you must type from a screen, exclude ambiguous characters and accept the smaller charset, or use a passphrase you can type carefully.
Practical habits that matter more than one number
- Prefer a password manager so each account gets a unique value.
- Do not reuse the sample above or any password you have seen on a public page.
- Rotate a guest Wi-Fi password when you print a QR; the password sits inside the code. See how to make a Wi-Fi QR code.
- If you want something easier to memorize than a dense string, compare bits with a word list in passphrase vs random password.
NIST SP 800-63B (revision 4) tells services (not individuals as personal advice) that a password used as the only factor must be at least 15 characters, that services should allow at least 64 characters, and that they must not impose composition rules or force periodic changes. The practical takeaway aligned with that document: length matters more than character mix, which is why this guide starts at 16 characters and then talks about charset size.
Length versus mix on real sites
Some sites still demand “one of each” character type. Meeting that rule with a short password can still leave a small search space. Prefer meeting their rule and pushing length up when the field allows it. Other sites accept long passphrases with spaces; this article’s random tab still helps when the field wants a dense string without spaces.
Store unique passwords per account. Reuse is how one breach becomes many. The entropy meter on this page is a teaching aid for the current toggles, not a promise about any specific attacker. If a site caps length below 16, generate at the maximum it allows, keep all character sets it accepts, and store the value in a manager so you are not tempted to reuse a shorter pattern across sites. When a site allows more than 16 characters, adding length is usually the cheapest way to raise the on-page entropy reading without fighting composition rules.
Try it
Set length 16, enable all four sets, leave exclude-ambiguous off, and compare the entropy line to about 102.6 bits. Copy only a value you just generated.
Frequently asked questions
Is Xh4!mK9pQ2$vL7nR a real password I should use?
No. It is a fake 16-character sample for this article. Generate a fresh value in the tool and never reuse published samples.
Does a higher entropy number guarantee safety?
No. Entropy estimates search-space size under the stated charset model. Phishing, reuse, and malware sit outside that number.
Should I turn on exclude ambiguous characters?
Use it when you will type the password by hand and want fewer lookalikes (O/0, I/l/1). Turning it on shrinks the charset and lowers entropy for the same length.
Passphrase or random password?
Use the passphrase comparison guide when you care about memorability versus bit count. This article focuses on the random password tab.
Does generation leave my browser?
Generation and copy run in your browser with your browser’s secure random number generator.
Related articles
Generators
Passphrase vs random password
Compare 4, 5 and 6-word passphrases from the 7,776-word EFF list with a 16-character random password using this site’s entropy math.
Generators
How to make a Wi-Fi QR code
Make a guest Wi-Fi QR with the generator’s Wi-Fi tab. Demo: Guest-Cafe. Anyone who scans can read the password.