In 2025 alone, over 10 billion credentials leaked online. The difference between a hacked account and a safe one is often a single strong password.
What makes a password strong?
- Length over complexity: 16+ characters beats any symbol rule
- No dictionary words, names or dates
- No reuse across websites
- Random, not human-chosen
- Managed by a password manager or encrypted notes
Generate a strong password now
- 1Open the Password Generator.
- 2Set length to 16-20 characters with all character types.
- 3Click Generate — passwords use the browser's cryptographically secure random source.
- 4Copy and store it in your password manager.
Check your existing passwords
Paste any password into the Password Strength Checker to see an entropy-based score with instant improvement suggestions. The checker runs entirely offline.
| Password | Length | Entropy | Crack time |
|---|---|---|---|
| password123 | 11 | 31 bits | Instantly |
| FluffyCat2020 | 12 | 41 bits | Minutes |
| Tr0ub4dor&3 | 11 | 45 bits | Days |
| xK9!mQ2#vR8$nP4@wT6 | 20 | 128 bits | Trillions of years |
Storing passwords safely
Never store passwords in plain text. Our Secure Notes encrypts your notes with AES-256 using a passphrase only you know — the data is decrypted locally and never transmitted.
The golden rules
- 1Use a unique password for every site
- 2Prefer passphrases of 4-5 random words (correct-horse-battery-staple)
- 3Enable 2FA everywhere it's offered
- 4Rotate passwords after any breach notification
- 5Never answer security questions truthfully — use random answers
The most common password of 2025 was still '123456'. It takes attackers 0.2 seconds to crack.