A brutally honest second opinion

DOES YOUR
PASSWORD
SUCK?

Get roasted. Get a replacement. Nothing leaves your device.

01 / THE ROAST

FEED IT A PATTERN.
KEEP YOUR SECRET.

We look for the tricks humans love and attackers already know. No corporate checkbox theater.

USE A LOOKALIKE.Same length. Same rhythm. Same substitutions. Different actual words.
LOCAL-ONLY INPUT

Up to 256 characters. Spaces and Unicode are welcome. Try a demo—these are examples, not suggestions.

Have you used this anywhere else?

Choose deliberately. Reuse changes the overall verdict even when the password itself is strong.

No form submission. No storage. No mysterious little marketing pixels.

01 MASKED BY DEFAULT02 NOTHING SAVED03 BREACH CHECK IS OPTIONAL

02 / THE REPAIR

FIX IT WITHOUT
BECOMING A ROBOT.

Make one strong, make it unique, and let a reputable password manager remember it. Your brain has other work.

A

MAXIMUM CHAOS

RANDOM PASSWORD

Generated with Web Crypto and unbiased rejection sampling. No Math.random. No tiny themed list pretending to be entropy.

2064

About 151 bits before any site-specific restrictions.

B

MAXIMUM HUMAN

SIX-WORD PASSPHRASE

Six independent selections from EFF’s bundled 7,776-word long list—roughly 77 bits under the stated model.

Good for places that accept long passwords. Keep all six words, separators, and uniqueness.

THE BORING ADVICE WORKS: Save a unique credential for every account in a reputable password manager. Turn on MFA. Use a passkey where supported.

03 / PASSWORD REALITY, UPDATED

THE TRAINING SLIDE
WAS WRONG.

Current guidance is less fussy and more useful: length, blocklists, uniqueness, and modern authentication beat ritual complexity.

01

MYTH

“Add one capital, one number, one symbol.”

REALITY

Predictable decorations do not rescue a predictable idea. Current NIST guidance rejects arbitrary composition rules.

02

MYTH

“Change it every 90 days.”

REALITY

Scheduled changes encourage tiny mutations. Change passwords when compromise is suspected or confirmed.

03

MYTH

“Fifteen characters means strong.”

REALITY

Fifteen is the current password-only minimum for services—not a force field. Common phrases can still be guessed.

04

MYTH

“A great password stops phishing.”

REALITY

Passwords are not phishing-resistant. Use MFA, and choose a passkey where the service supports one.

15

CURRENT NIST SP 800-63B-4

PASSWORD-ONLY AUTHENTICATION: MINIMUM 15 CHARACTERS.

A shorter minimum is permitted only when the password is used with MFA, and then it must still be at least eight. Services should support long passwords (at least 64 characters), accept spaces and Unicode, reject common or compromised values, avoid arbitrary composition rules, skip forced periodic changes absent compromise, and allow password managers, autofill, and paste. Passwords are not phishing-resistant.

04 / RECEIPTS, NOT VIBES

WHAT THIS PAGE
CAN & CANNOT KNOW.

CAN ESTIMATE

  • Patterns in the value currently held in this tab
  • An order-of-magnitude guess count under zxcvbn-ts’s model
  • The reuse answer you provide
  • HIBP corpus presence—but only after your explicit check

CANNOT KNOW

  • How any specific website stores or rate-limits passwords
  • An attacker’s hardware, personal clues, or strategy
  • Whether your “No” on reuse is actually true
  • Future breaches—or whether a not-found value is safe
  • Whether you will be phished tomorrow

PRIVACY

EPHEMERAL BY DESIGN.

The test value and generated values live only in this page’s working memory. They are not submitted, logged, placed in a URL, written to local or session storage, saved in cookies, or kept in a generated-password history. Reset clears them, and the page attempts to clear them when discarded. There are no ads, analytics, session replay, crash reporting, remote fonts, or third-party runtime scripts.

METHOD

PATTERNS, NOT CHECKBOXES.

The local estimator is zxcvbn-ts with bundled English and common dictionaries. It looks for common passwords, words, names, dates, keyboard walks, repeats, sequences, and predictable substitutions. Guess counts and time buckets are illustrative estimates based on stated assumptions.

LIMITATIONS

NOT A SECURITY AUDIT.

Models can under- or overestimate unfamiliar language, Unicode, personal information, and attacker knowledge. A strong result is not a guarantee. A breach miss is not proof. The safest input here remains a made-up lookalike, not a credential you use.

05 / FAIR QUESTIONS

YES, WE
THOUGHT OF THAT.

Can I paste my real password?

Please don’t. A privacy promise does not turn a random website into the right place for a live credential. Use a made-up value with the same pattern.

Does “not found” in HIBP mean safe?

No. It only means the exact value was not found in HIBP’s current indexed corpus. It says nothing about future breaches, uniqueness, or guessability.

Why not award points for uppercase, numbers, and symbols?

Because “Password1!” checks those boxes and remains painfully predictable. Pattern-aware analysis asks a better question: what would a smart guesser try?

Why six EFF words?

EFF’s long list has 7,776 words. Six independent uniform selections provide roughly 77 bits under that model while remaining more typeable than random character soup.

What should I actually do?

Use a reputable password manager, give every account a unique credential, enable MFA, and choose a passkey where supported. Change a password promptly when compromise is suspected.