P
Guides
Language
Tools
Password & Security
P
Password Strength Checker
Score any password and estimate crack time
P
Password Generator
Create strong random passwords up to 128 chars
R
Random String Generator
Random tokens, IDs and keys with any charset
P
Passphrase Generator
Memorable multi-word passphrases (Diceware)
T
TOTP / 2FA Code Generator
Time-based one-time codes and otpauth secrets
P
Password Breach Checker
Check if a password appeared in known breaches
Hash & Crypto
S
SHA-256 Generator
Hash text to a 64-char SHA-256 digest
M
MD5 Generator
Compute the 32-char MD5 checksum of any text
S
SHA-1 Generator
Generate the 40-char SHA-1 hash of any input
S
SHA-512 Generator
Hash text to a 128-character SHA-512 digest
H
HMAC Generator
HMAC-MD5, SHA-1, SHA-256 & SHA-512 with secret key
B
bcrypt Generator / Checker
Hash passwords with bcrypt and verify hashes
P
PBKDF2 Key Derivation
Derive keys from a password with salt and iterations
A
AES Encrypt / Decrypt Text
Encrypt text with AES-256-GCM and a password
F
File Hash / Checksum
Compute SHA hashes of any file locally
Networking
I
IP Address Checker
Identify IPv4 vs IPv6, public/private and more
I
IPv4 Calculator
Network, broadcast, hosts, subnet mask & wildcard
I
IPv6 Calculator
Expand, compress and subnet IPv6 addresses
S
Subnet Calculator
CIDR ranges, wildcard masks and usable hosts
M
MAC Address Generator
Random valid MAC addresses, unicast or multicast
P
Port Checker
Learn what each TCP/UDP port number means
D
DNS Lookup
Resolve A, AAAA, MX, NS, TXT and CNAME records
W
WHOIS Lookup
Domain registration, expiry and registrar info
Web & HTTP
H
HTTP Header Analyzer
Security, caching & SEO headers explained
U
User-Agent Parser
Decode browser, OS and device from any UA
M
MIME Type Lookup
File extension to MIME type reference
H
HTTP Status Code Lookup
Every status code 1xx–5xx explained
U
URL Encoder / Decoder
Percent-encode URLs and parse query strings
C
Color Contrast Checker (WCAG)
Check text contrast against WCAG AA & AAA
Developer Utilities
U
UUID / ULID Generator
UUID v4, v7, ULID and NanoID in bulk
J
JWT Decoder & Signer
Decode, inspect and sign JSON Web Tokens
B
Base64 Encoder / Decoder
Encode and decode Base64, standard or URL-safe
Q
QR Code Generator
QR codes for links, Wi-Fi and vCards
J
JSON Formatter & Validator
Format, minify and validate JSON instantly
T
Unix Timestamp Converter
Convert Unix timestamps to dates and back
R
Regex Tester
Test regular expressions with live matches
D
Diff Checker
Compare two texts and highlight differences
L
Lorem Ipsum Generator
Placeholder paragraphs, sentences or words
N
Number Base Converter
Convert between binary, octal, decimal and hex
C
Color Converter (HEX / RGB / HSL)
Convert colors and copy HEX, RGB or HSL
C
CSV to JSON Converter
Convert CSV to JSON and JSON back to CSV
C
Case Converter & Slug Generator
camelCase, snake_case, kebab-case, Title & slug
W
Word & Character Counter
Words, characters, sentences and reading time
Passwords

What Makes a Password Strong?

Strength is not about symbols — it is about unpredictability. Understand entropy and the few rules that actually keep accounts safe.

Updated 16 September 2026 · 8 min read
Advertisement

Strength is unpredictability

A password's strength is how many guesses an attacker must make to find it. That is measured in entropy (bits). Symbols help a little; length and randomness help a lot.

Test yours with the password strength checker.

Entropy in one picture

Password Rough entropy
Password1 Very low
Tr0ub4dor&3 ~28 bits
correct horse battery staple ~44 bits
4 random words + a number 50+ bits

Adding characters multiplies the search space; swapping letters for symbols barely moves it.

The rules that actually work

  1. Use 14+ characters — or a 4–5 word passphrase.
  2. Make it random — do not build it from personal facts.
  3. Unique per site — never reuse.
  4. Use a password manager — it removes the memory problem.
  5. Turn on two-factor authentication (2FA) — the single biggest win.

Generate strong ones with the password generator.

Why reuse is the real danger

When one site is breached, attackers try the same email/password everywhere ("credential stuffing"). One reused password can unlock your email, banking and social accounts. Unique passwords break that chain.

Passphrases: strong and memorable

Random words are strong because the number of word combinations is enormous:

copper-lantern-orbit-mango

For a human, this is easier to remember than x7#Qp!2 and far stronger.

What to avoid

  • Personal details: names, birthdays, pet names.
  • Patterns: qwerty, 123456, abcdef.
  • Single dictionary words and common substitutions (p@ssw0rd).
  • Reusing a password across accounts.
  • Sharing passwords over chat or email.

Beyond the password

  • 2FA / MFA — codes or hardware keys.
  • Passkeys — phishing-resistant, increasingly available.
  • Breach monitoring — change passwords for any account in a leak.

Check and improve

Measure any password's strength with the strength checker and generate replacements with the generator — all computed locally in your browser.

Advertisement
Help Center

What Makes a Password Strong? — FAQ

Generally yes. Length adds far more entropy than complexity. A long passphrase of random words beats a short string of symbols.

Reputable ones are far safer than reusing passwords. They store your vault encrypted, and you only need to remember one strong master password.

Only when there is a reason — a breach or suspected compromise. Forced periodic changes tend to weaken passwords by encouraging predictable variations.

Keep reading
Advertisement