MAXIMUM CHAOS
RANDOM PASSWORD
Generated with Web Crypto and unbiased rejection sampling. No Math.random. No tiny themed list pretending to be entropy.
About 151 bits before any site-specific restrictions.
A brutally honest second opinion
Get roasted. Get a replacement. Nothing leaves your device.
01 / THE ROAST
We look for the tricks humans love and attackers already know. No corporate checkbox theater.
02 / THE REPAIR
Make one strong, make it unique, and let a reputable password manager remember it. Your brain has other work.
MAXIMUM CHAOS
Generated with Web Crypto and unbiased rejection sampling. No Math.random. No tiny themed list pretending to be entropy.
About 151 bits before any site-specific restrictions.
MAXIMUM HUMAN
Six independent selections from EFF’s bundled 7,776-word long list—roughly 77 bits under the stated model.
Good for places that accept long passwords. Keep all six words, separators, and uniqueness.
THE BORING ADVICE WORKS: Save a unique credential for every account in a reputable password manager. Turn on MFA. Use a passkey where supported.
03 / PASSWORD REALITY, UPDATED
Current guidance is less fussy and more useful: length, blocklists, uniqueness, and modern authentication beat ritual complexity.
MYTH
REALITY
Predictable decorations do not rescue a predictable idea. Current NIST guidance rejects arbitrary composition rules.
MYTH
REALITY
Scheduled changes encourage tiny mutations. Change passwords when compromise is suspected or confirmed.
MYTH
REALITY
Fifteen is the current password-only minimum for services—not a force field. Common phrases can still be guessed.
MYTH
REALITY
Passwords are not phishing-resistant. Use MFA, and choose a passkey where the service supports one.
CURRENT NIST SP 800-63B-4
A shorter minimum is permitted only when the password is used with MFA, and then it must still be at least eight. Services should support long passwords (at least 64 characters), accept spaces and Unicode, reject common or compromised values, avoid arbitrary composition rules, skip forced periodic changes absent compromise, and allow password managers, autofill, and paste. Passwords are not phishing-resistant.
04 / RECEIPTS, NOT VIBES
CAN ESTIMATE
CANNOT KNOW
PRIVACY
The test value and generated values live only in this page’s working memory. They are not submitted, logged, placed in a URL, written to local or session storage, saved in cookies, or kept in a generated-password history. Reset clears them, and the page attempts to clear them when discarded. There are no ads, analytics, session replay, crash reporting, remote fonts, or third-party runtime scripts.
METHOD
The local estimator is zxcvbn-ts with bundled English and common dictionaries. It looks for common passwords, words, names, dates, keyboard walks, repeats, sequences, and predictable substitutions. Guess counts and time buckets are illustrative estimates based on stated assumptions.
LIMITATIONS
Models can under- or overestimate unfamiliar language, Unicode, personal information, and attacker knowledge. A strong result is not a guarantee. A breach miss is not proof. The safest input here remains a made-up lookalike, not a credential you use.
05 / FAIR QUESTIONS
Please don’t. A privacy promise does not turn a random website into the right place for a live credential. Use a made-up value with the same pattern.
No. It only means the exact value was not found in HIBP’s current indexed corpus. It says nothing about future breaches, uniqueness, or guessability.
Because “Password1!” checks those boxes and remains painfully predictable. Pattern-aware analysis asks a better question: what would a smart guesser try?
EFF’s long list has 7,776 words. Six independent uniform selections provide roughly 77 bits under that model while remaining more typeable than random character soup.
Use a reputable password manager, give every account a unique credential, enable MFA, and choose a passkey where supported. Change a password promptly when compromise is suspected.