๐Ÿ› ๏ธ Developer ยท Updated October 11, 2026 ยท 6 min read

Create a Strong Password: Random, Passphrase or PIN

Weak Strong ๐Ÿ”‘

To create a strong password, use a random generator set to at least 16 characters with uppercase, lowercase, numbers and symbols, or a passphrase of six or more random words, then save the result in a password manager and never reuse it. With the default settings, a 16-character random string is drawn from a 70-character pool and carries about 98 bits of entropy; even at 10 billion guesses per second, an offline attacker would need hundreds of billions of years on average. GrabCast's Password Generator builds random strings, EFF word-list passphrases and PINs with your browser's cryptographic random source, shows the entropy and crack time for each, and can create up to 500 at once. This guide explains which type to use where, the settings that actually matter, what the strength meter does and does not tell you, and the habits, uniqueness and two-factor sign-in, that keep a good password from being wasted.

๐Ÿ”‘ Try the Password Generator tool now โ€” freeOpen โ†’
Password generator showing an 18-character random password with a strong entropy reading
A strong random password.
๐Ÿ’ก Why random beats clever every time

Most account takeovers are not clever hacks. Attackers replay passwords leaked from one site against email, banking and shopping logins, a technique called credential stuffing, and they crack the rest with lists of dictionary words, names, dates and common substitutions such as @ for a and 0 for o, because that is how people invent passwords. Summer2026! looks complex and falls in seconds to those rules. A generator removes the human pattern entirely: every character or word is drawn with equal probability from a known pool, so the only attack left is brute force, and length makes brute force hopeless. GrabCast uses crypto.getRandomValues with rejection sampling, which avoids the subtle bias of simpler random functions, and nothing is transmitted or stored.

Create a strong password by choosing where you will type it

The tool has three tabs, and each fits a different situation:

Passphrases draw from the Electronic Frontier Foundation's large word list of 7,776 words, so each word adds 12.9 bits. Six words give about 77.5 bits, far easier to type on a phone than 13 random symbols of similar strength.

Settings that matter, and the ones that barely do

Length dominates everything. Each extra random character multiplies the number of possibilities by the pool size, so going from 12 to 16 characters multiplies the work by about 25 million.

If a site caps length at 12 or 16, max it out and let a password manager store it.

Read the strength meter correctly

Every result shows bits of entropy, a rating from Very weak to Very strong, and two average crack times: offline at 10 billion guesses per second, which models a stolen database, and online at 100 guesses per second, which models someone typing at a login page. Some reference points from the tool's own math:

The math assumes the attacker knows your settings, the honest worst case. It cannot protect a password you reuse, type into a phishing page or share, so uniqueness and two-factor authentication still matter.

Store it, generate in bulk and keep it private

A strong login is useless if it ends up on a sticky note. Paste each new one straight into a password manager such as Bitwarden, 1Password, Apple Passwords or Google Password Manager, then turn on two-factor authentication for email, banking and your manager itself.

Everything happens in your browser. The passphrase word list is the only file fetched, and nothing you create is sent or logged.

To test existing logins, the Password Breach Checker helps, and this guide to free tool safety shows what to check in any generator.

Step-by-step

1234
1Open the Password Generator and pick a tab: Password for manager-filled logins, Passphrase for secrets you type, PIN for lockout-protected devices.
Password generator on the Password tab beside the Passphrase and PIN tabs, with the length and character options
Pick the Password tab for manager-filled logins.
2Set the length to 16 to 20 characters, or six or more words, and keep uppercase, lowercase, numbers and symbols checked unless a site forbids them.
Length slider set to 18 characters with uppercase, lowercase, numbers and symbols ticked
Set the length to 16 to 20 characters.
3Check the entropy and crack-time line, press the refresh arrow for a new result, and click Copy.
A generated 18-character password with the strength meter, bits of entropy and crack-time line and a Copy button
Check the entropy line, then copy.
4Paste it into the account and save it in your password manager at once; use Generate many at once for batches.

Common mistakes to avoid

โš ๏ธReusing one strong password across accounts, so a single breach unlocks all of them.
โš ๏ธChoosing 8 characters because a site allows it, when 16 costs you nothing with a manager.
โš ๏ธUsing a PIN or a short word as an online login, where there is no lockout to protect it.
โš ๏ธLeaving a bulk .txt list of credentials on the desktop after handing them out.

Pro tips

โœ“Make your password manager's master key a passphrase of seven words; it is the one secret you must remember.
โœ“Turn off look-alike avoidance only when nobody will ever need to read the code aloud; otherwise leave it on.
โœ“When a site rejects a symbol, remove it in Never use these characters instead of switching symbols off entirely.
โœ“Change a login immediately if the service reports a breach; generate a fresh one rather than editing the old.
โœ“Use a unique password on every site and a separate email address for recovery on your most important services, so one leak cannot cascade.

Frequently asked questions

How long should a strong password be?

At least 16 random characters for accounts a password manager fills in, or six random words for a passphrase you type. Both are far beyond practical brute-force attacks.

Is a passphrase as secure as a random password?

Yes, if the words are chosen randomly. Six words from the 7,776-word EFF list give about 77.5 bits, similar to 13 random characters, and seven words give about 90 bits.

Is it safe to generate passwords online?

It is when generation happens on your device. GrabCast uses the browser's cryptographic random generator and sends nothing to a server; only the passphrase word list is downloaded.

What does bits of entropy mean?

It measures how many guesses an attacker would need. Each extra bit doubles the work, so 80 bits is about a thousand times harder than 70.

Can I generate many passwords at once?

Yes. Open Generate many at once, choose up to 500, then copy them all or download a .txt file. Delete the file once the credentials are distributed.

๐Ÿ“Œ Bottom line

To create a strong password, rely on randomness and length, not clever substitutions. Use 16 or more random characters for logins your password manager fills, a six or seven word passphrase for the few you must type, and PINs only where a lockout protects them. GrabCast's generator shows the entropy and crack time for each result, creates batches of up to 500, and does it all on your device. Store every result in a manager, never reuse one, and add two-factor authentication to the accounts that matter most.

Open the Password Generator tool โ†’

Related guides

Browse more: all text and developer guides ยท the Password Generator tool