Choosing and generating a strong password

A "complicated" password isn't necessarily strong. What resists an attack is, above all, unpredictability - and that comes mostly from length.

Length first

Each extra character multiplies the number of combinations to test. A long random 16-character password is out of reach for brute force, while a short one packed with symbols stays vulnerable if it's short. Aim for length before complexity.

💡 Anecdote - The XKCD comic popularized the idea that four random words ("correct horse battery staple") are both safer and easier to remember than a "Tr0ub4dor&3".

Random, not "clever"

The usual substitutions (a@, e3) are well known to attackers and add almost nothing. A real generator draws characters at random, with no guessable pattern. Ideally, a unique password per site, kept in a manager.

Generate without leaking

A password should never travel through a server at creation time. Our password generator draws characters locally, in your browser: the value is neither sent, stored, nor logged

🤓 Did you know? The first computer password (MIT's CTSS system, 1961) was also the first to leak: in 1962, a researcher printed the password file to grab more computing time than his share.