Generate a strong password
Generate a random password locally using the browser cryptography API.
Generate a unique password for every account
Choose the length and allowed character types, then generate a random password locally in your browser. Copy it directly into a password manager rather than reusing it across services.
What makes a password stronger?
- Length: longer passwords have a much larger possible search space.
- Uniqueness: one compromised service should not expose another account.
- Randomness: predictable substitutions and personal details are easier to guess.
- Secure storage: a reputable password manager is safer than memorising many variations.
Current NIST digital-identity guidance treats password length as a primary strength factor and advises services not to rely on mandatory character-composition rules alone. Randomly generated passwords can still use mixed character types when the website accepts them.
Practical recommendations
| Use | Practical approach |
|---|---|
| Password-manager login | Use a long, memorable passphrase and enable multi-factor authentication |
| Normal website account | Use a unique randomly generated password stored in your manager |
| High-value account | Use a long unique password plus phishing-resistant MFA where available |
Frequently asked questions
Does ToolCetra store generated passwords?
No. Generation runs in your browser. Still avoid generating or copying passwords on a device you do not trust.
Should I change passwords regularly?
Change a password when it may be compromised, reused or exposed. Routine forced changes can encourage weaker predictable variations.
Are passphrases better?
Passphrases are useful when you need to remember the secret yourself. For stored account credentials, a long random password is usually convenient.
Source context: NIST SP 800-63B. For memorable multi-word output, use the Passphrase Generator.