>_ PassSmith
Unlimited Free Usage Generated locally — never leaves your browser
passsmith@secure: ~/vault — zsh
20
4128

$ character sets --sets

$ hardening flags

output

$ press ./generate ⏎▊

strength —

entropy

—

crack time

—

pool size

—

length

—

Crack-time assumes 10 billion guesses/sec (modern GPU cluster, offline attack). Average case = half the keyspace.

session history (this browser only)

    No passwords generated yet this session. History is stored only in your browser's localStorage.

    Privacy: every password is forged with crypto.getRandomValues — your browser's cryptographically secure RNG. This page makes zero network requests for generation; your passwords are generated locally and never leave your browser.

    The Complete Guide to Strong Passwords: Generation, Entropy, and Passphrases

    By the PassSmith security desk · Last updated September 2026

    Why your password is probably the weakest link

    Every year, security researchers publish the same depressing league table: the most common passwords on the internet are still variations of "123456", "password", and "qwerty". Attackers know this. Modern credential-stuffing attacks do not bother guessing clever combinations first — they simply try the few million passwords that humans actually use, across thousands of websites, at machine speed. If your password is a word, a name, a date, or a predictable pattern, it falls in the first wave. The uncomfortable truth is that human brains are terrible random-number generators. We pick what feels random — a capital letter at the start, a number at the end, an exclamation mark for decoration — and millions of other people pick the same thing. A password generator exists to remove the human from the randomness equation entirely. Instead of inventing something that feels secure, you let a cryptographic random-number generator assemble characters with no pattern, no memory, and no bias. The result looks like nonsense precisely because it is: every position is independent of every other position, and that independence is what makes brute-force guessing astronomically expensive.

    How PassSmith forges a password

    PassSmith never invents its own randomness. It asks your browser for it. The Web Crypto API — specifically the crypto.getRandomValues() function — draws bytes from the operating system's cryptographically secure pseudorandom number generator, the same source of entropy your browser uses for TLS session keys. This matters because the older Math.random() function found in tutorials was designed for games and animations, not security; its output can be predictable if an attacker observes enough of it. PassSmith maps those secure bytes onto your chosen character sets using rejection sampling, a technique that discards any byte value that would introduce modulo bias, so every character in the pool has an exactly equal chance of appearing. When you enable character sets, the generator also guarantees coverage: it first places one character from each enabled set, then fills the remaining positions, then shuffles the whole string with a Fisher–Yates shuffle driven by the same secure source. That means the guaranteed uppercase letter is never sitting smugly at the front where an attacker would expect it. Everything happens inside your browser tab. No request is sent anywhere, no server logs anything, and closing the tab leaves no trace beyond the optional history you can clear with one click.

    Random strings vs. memorable passphrases

    There are two philosophies of password creation, and PassSmith speaks both fluently. The classic approach is a random string: twenty characters drawn from upper and lower case, digits, and symbols. It is maximally compact — every character carries several bits of entropy — but it is also maximally hostile to human memory, which is why people either write it on a sticky note or reuse it everywhere, defeating the point. The alternative is the passphrase: several ordinary words strung together, like "correct horse battery staple", the famous example from a well-known webcomic about password strength. A passphrase trades per-character density for length and memorability. Four random words from a 200-word list give roughly 30 bits of entropy each from the word choice alone, and a six-word passphrase lands near 46 bits — comparable to a strong random password, but something you can actually type from memory while looking at a login screen across the room. PassSmith's passphrase mode draws words with the same cryptographic RNG, lets you pick a separator (dash, space, underscore, dot, or none), optionally capitalizes each word, and can append a random digit for sites with fussy complexity rules. The honest guidance: use random strings for accounts behind a password manager, where you never need to remember or type them, and use passphrases for the handful of secrets you must carry in your head — your master password, your device PIN-adjacent secrets, your disk-encryption passphrase.

    Entropy: the one number that measures password strength

    Forget "password strength meters" that reward you for adding an exclamation mark. The serious measure of a password's resistance to guessing is entropy, expressed in bits. The formula is disarmingly simple: entropy equals length multiplied by the base-2 logarithm of the pool size. A 20-character password drawn from 94 possible characters (upper, lower, digits, symbols) has about 131 bits of entropy. What does that mean in practice? It means an attacker guessing at random would need, on average, to try half of all 2^131 possibilities — a number so large that writing it out requires 40 digits. Every additional bit doubles the attacker's work, which is why length beats complexity: adding one character to a lowercase-only password adds about 4.7 bits, while swapping a letter for a symbol in a short password adds far less than people imagine. PassSmith displays the entropy of everything it generates, live, so you can watch the number climb as you drag the length slider. As a rule of thumb used by security practitioners: anything under 40 bits is weak, 40 to 60 bits is fair, 60 to 80 is strong, 80 to 100 is very strong, and above 100 bits is effectively uncrackable by brute force with any technology on the horizon. The passphrase math works the same way, except the "pool" is the word list and the "length" is the word count — six words from a 200-word list is about 46 bits before separators and capitalization are even counted.

    From entropy to crack time: what the estimate really assumes

    Entropy in bits is precise but abstract, so PassSmith translates it into a crack-time estimate: how long a brute-force attack would take on average. The estimate assumes an offline attack running at ten billion guesses per second — roughly what a modern multi-GPU rig can sustain against a fast hash. Under that assumption, the average crack time is half the keyspace divided by the guess rate. A 12-character mixed password at about 79 bits falls in roughly six months; push it to 16 characters and you are suddenly past forty thousand years. These numbers come with honest caveats that any reputable tool should state. First, they assume pure brute force; real attackers try dictionaries, leaked-password lists, and mangling rules first, which is why "P@ssw0rd2024!" crumbles in seconds despite looking complex. Second, they assume a fast hash — if a site stores passwords with a slow, salted algorithm like bcrypt or Argon2, the effective guess rate collapses by orders of magnitude and even modest passwords survive. Third, online guessing against a live login page is throttled by rate limits and lockouts, so the offline scenario is the conservative, worst-case model. The estimate's real value is comparative: it shows you, instantly, that two extra characters buy more security than any amount of symbol-swapping cleverness.

    The ambiguous-character problem nobody talks about

    Ask anyone who has ever read a password over the phone, or squinted at one in a small terminal font, which characters cause the most grief. The hall of shame is short: capital I, lowercase l, the digit 1, capital O, and the digit 0. In many fonts, "Il1" is a trio of vertical strokes and "O0" a pair of ovals — indistinguishable. A password you cannot transcribe accurately is a password that locks you out, generates a support ticket, or gets written down somewhere unsafe. That is why PassSmith ships with "exclude ambiguous characters" enabled by default, stripping those confusables from the pool. The entropy cost is tiny — removing six characters from a 94-character pool shaves about half a bit per character — and the usability gain is enormous. A related option, "no repeat characters", guarantees every character appears at most once, which is handy for PIN-style codes and some legacy systems with odd constraints, though you should know it slightly reduces the pool for very long passwords (a 40-character password from a 94-character pool without repeats is still overwhelmingly strong). Small flags, real-world difference: the best password is one you can actually use without friction.

    Bulk generation: ten passwords in one click

    Most generator tools make you click "generate" ten times to get ten passwords, copying each one before it vanishes. PassSmith's bulk mode produces ten passwords at once from your current settings, each with its own copy button plus a copy-all option that drops the whole batch onto your clipboard. This is not a gimmick — it matches how passwords are actually provisioned in the real world. Onboarding a team means creating accounts across a dozen services. Rotating credentials after a scare means replacing every password at once. Setting up a homelab means credentials for the router, the NAS, the media server, the containers, and the Wi-Fi guest network. Developers seeding test environments need dummy credentials that still look realistic. In each case, the workflow is "generate a batch, paste them where they belong, done" — and because every password in the batch is drawn independently from the cryptographic RNG, there is no relationship between them for an attacker to exploit. Bulk mode reuses your random-mode configuration, so set the length and character sets once, then harvest.

    Passwords in a password-manager world

    The single highest-leverage security upgrade most people can make is not a longer password — it is a password manager. Reusing one decent password across fifty sites means a breach at the weakest site hands attackers the keys to the other forty-nine, and breach compilations containing billions of credentials circulate freely. A manager inverts the economics: it remembers a unique, 20-plus-character random password per site, so you only need to memorize one strong master passphrase — ideally a six-word diceware-style passphrase, exactly what PassSmith's passphrase mode produces. Turn on two-factor authentication everywhere it is offered, prefer authenticator apps or hardware keys over SMS codes, and treat your email account as the crown jewels, since password resets flow through it. For the accounts you cannot put behind a manager — device encryption, the manager's own master password — a memorized passphrase is the right tool. Everything else should be random, unique, and forgotten by you on purpose. That is the entire philosophy in one sentence: humans remember a few passphrases; machines remember everything else.

    A note on privacy and trust

    A password generator asks for an unusual kind of trust: you are letting a webpage create the keys to your digital life. The only sane architecture for that trust is verifiable client-side generation. PassSmith's generation code runs entirely in your browser, uses the platform's secure random source, and sends nothing anywhere — there is no account, no analytics event carrying your password, no server to be breached. The optional history lives in your browser's localStorage, masked by default, and can be wiped instantly. If you are ever unsure about any generator, the test is simple: open your browser's developer tools, watch the network tab while generating, and confirm silence. Healthy paranoia, satisfied. Combine that with unique passwords per site, a reputable password manager, and two-factor authentication, and you have closed the easiest doors attackers walk through every day.

    $ faq --help

    Is PassSmith really free? Are there limits?

    Yes — unlimited free usage, no signup, no paywall, no watermark. Generate as many passwords or passphrases as you like, in any quantity, forever.

    Do my generated passwords leave my browser?

    No. Every password is generated locally with your browser's cryptographically secure RNG (crypto.getRandomValues). The page makes zero network requests during generation, and nothing is ever transmitted or stored on a server.

    Should I use a random password or a passphrase?

    Use random passwords for accounts stored in a password manager (you never type them), and memorable passphrases for the few secrets you must remember — like your master password or disk encryption. PassSmith offers both modes.

    What does the entropy readout mean?

    Entropy, in bits, measures how many guesses an attacker needs on average: length × log₂(pool size). Higher is stronger — above 80 bits is very strong, and above 100 bits is effectively uncrackable by brute force.

    How is the crack-time estimate calculated?

    It divides half the keyspace (the average brute-force case) by 10 billion guesses per second, approximating a modern GPU cluster attacking an offline hash. It is a conservative worst-case model; rate-limited online logins are far slower to attack.

    Why exclude ambiguous characters?

    Characters like I, l, 1, O, and 0 look identical in many fonts, causing transcription errors when you read or type a password. Excluding them costs almost no entropy but removes a real-world source of lockouts.