thoughtasylumTOOLBOX Preview

Tools › Ciphers

Password Generator

Strong passwords, XKCD-style passphrases of random words, PINs, API keys, hex and URL-safe tokens and slug IDs, with GRC's Password Haystack figures for how long a brute-force search would take, and a check of any password for common words and patterns.

About this tool What it's for, how to use it and an example

What it's for

Make strong passwords, easy-to-remember passphrases of random words, PINs, and random strings for developers (API keys, tokens and IDs), and see how long a brute-force search would take to find them.

  • When you’re creating an account and want a long random password for your password manager to keep.
  • When you need something you can remember and type, such as your password manager’s own password: a passphrase of four or more random words, as in xkcd’s “correct horse battery staple”.
  • When you need a random API key, secret or ID for an app: an API key with a prefix such as sk_, a hex or URL-safe token, or a short slug.
  • When you want to see how much harder length and different kinds of character make a password to find.

How to use it

Choose what to make and how many, from 1 to 50; each has a Copy button, and Generate makes a new set. Copy all, under the list, copies the whole set shown, one per line. Settings are remembered.

  • Passphrase of words picks words at random from the EFF’s list of 7,776 words. Choose how many, what goes between them, capitals, and digits or symbols on the end.
  • Random characters picks from the kinds of character you tick, and every kind you tick is included at least once.
  • PIN is random digits.
  • API key is random Base62 characters (0-9, A-Z, a-z), 8 to 128 of them, with an optional prefix such as sk_ put in front.
  • Hex token is 8 to 64 random bytes written as hex, so 32 bytes make 64 characters.
  • URL-safe token is 8 to 64 random bytes in base64url (A-Z, a-z, 0-9, - and _, no = padding), safe in a link or filename.
  • URL slug ID is lowercase letters and digits, 4 to 64 of them, for short IDs in addresses.

Under each set is the entropy as generated (a prefix is fixed, so it adds none): how many equally likely passwords these settings can make. Password Haystack measures the first password, or whichever you choose by name, or one you type: it gives the figures from Steve Gibson’s Password Haystacks at GRC for a brute-force search of every password of that length and those kinds of character.

A brute-force search is the worst case. Real crackers try common passwords, words and patterns first, so for a password you type, Weak spots lists what would make it fall much sooner: a common password (even with @ for a or 0 for o), a dictionary word, a run of neighbouring keys, repeats, a year, or the usual capital-word-digits shape. Spell it out beside each password gives it in the phonetic alphabet, for reading it out over the phone.

Example

Type this in Password to measure:

Password

The search space depth is 26 + 26 = 52, and an online attack takes 17.33 centuries, as on GRC’s page. Now type 123456: 18.52 minutes.

Good to know

Passwords are made with the browser’s cryptographic random number generator and never leave the page. The Haystack is a brute-force measure: it assumes the attacker tries every combination, so it rates common passwords such as Password far too highly, and a passphrase of dictionary words higher than an attacker who knows the word list would find it. The entropy as generated assumes the attacker knows exactly how it was made, so it’s the safer figure for generated passwords. The word list is the EFF’s Long Wordlist, used under CC BY 3.0 US.

Password Haystack

    Calculated as in Steve Gibson's Password Haystacks at GRC, which explains what the figures mean and how padding makes a password harder to find. Passphrases follow xkcd 936, “correct horse battery staple”.

    Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

    Saved you a few minutes? Say thanks with a coffee.

    Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

    ↑ ↓ move↵ openesc close