Strong Password & Memorable Passphrase Generator
Create uncrackable random passwords, memorable Diceware passphrases, and secure numeric PINs using native hardware entropy. Measure bit entropy and brute-force crack resilience with zero server tracking.
No past passwords yet in this session.
The Cryptographic Guide to Password Entropy & Offline Brute-Force Defense
Learn how cryptographically secure pseudorandom number generators (CSPRNG) protect against rainbow table attacks, GPU hash cracking, and credential stuffing.
Brute-Force Crack Time Benchmarks by Character Pool & Length
The table below demonstrates how mathematical entropy scales exponentially. Estimates assume a modern brute-force attack cluster calculating 100 billion hash guesses per second ($10^{11}$ hashes/sec):
| Length & Character Set | Possible Combinations | Entropy (Bits) | Estimated Crack Time |
|---|---|---|---|
| 8 Chars (Lowercase Only) | 2.08 × 10¹¹ | 37.6 Bits | Instant (< 2 seconds) |
| 8 Chars (Upper + Lower + Numbers) | 2.18 × 10¹⁴ | 47.6 Bits | ~ 36 minutes |
| 12 Chars (All Sets + Symbols) | 4.75 × 10²³ | 78.6 Bits | ~ 150,000 Years |
| 16 Chars (All Sets + Symbols) | 3.71 × 10³¹ | 104.8 Bits | Trillions of Centuries |
| 5-Word Diceware Passphrase | 3.57 × 10¹⁹ | 64.6 Bits | ~ 11,000 Years |
Frequently Asked Questions (FAQ)
Why is Math.random() insecure for generating passwords?
Standard Math.random() is a PRNG designed for graphics and simulations, not cryptography. Its internal state can be reconstructed by an attacker who observes a sequence of outputs. In contrast, window.crypto.getRandomValues() uses OS entropy buffers with cryptographically proven randomness.
What is a Diceware passphrase?
Created by Arnold Reinhold, Diceware is a method of creating secure passphrases by stringing together random, real dictionary words. Because each word contributes approximately 12.9 bits of entropy, a 5-word passphrase is mathematically impossible to crack while remaining simple to memorize.
Are any generated passwords stored on 360tools servers?
No. Zero network requests occur. When you close or refresh this tab, all session history is immediately garbage collected from your browser RAM.