Security Tools · · 4 min read
How to Create a Strong Password (and How Strong Is "Strong"?)
What actually makes a password strong, how entropy is measured, how long your passwords should be, and how to generate secure random ones for free.
A strong password is long and random. The simplest way to get one is to use a generator that relies on your device's cryptographically secure random number source — like the Toolbench Password Generator — and to set the length to at least 16 characters. Then store it in a password manager so you never have to remember it.
This guide explains why length beats cleverness, what the "bits of entropy" number means, and how to choose settings for different situations.
What makes a password strong?
Attackers don't guess passwords one at a time by hand. They run software that tries billions of combinations, starting with leaked passwords, dictionary words and predictable patterns like Summer2026!. A password is strong when it:
- Isn't in any leaked list or dictionary — which rules out anything a human invented.
- Is long enough that trying every combination is impractical.
- Is unique to one account, so a breach elsewhere can't unlock it.
Randomness handles the first point, length handles the second and a password manager handles the third.
How to generate a password with Toolbench
- Open the Password Generator.
- Drag the length slider (6 to 64 characters; it starts at 20).
- Choose character sets: A–Z, a–z, 0–9 and !@#$ symbols.
- Turn on Avoid look-alikes if the password will ever be read aloud or typed from paper — it removes characters like
l,1,I,O,oand0. - Copy the main password, or pick one of the four alternatives below it. Click Regenerate for a fresh set.
Passwords are generated with your browser's crypto.getRandomValues() — the same cryptographically secure source browsers use for encryption keys. They are created on your device and never sent anywhere or saved.
What "bits of entropy" means
Next to each password, the generator shows an estimate like "≈ 129 bits entropy". Entropy measures how many guesses a brute-force attack would need, on a doubling scale: every extra bit doubles the work.
For a truly random password it's calculated as:
entropy = length × log₂(number of possible characters)
With all four character sets on, there are 87 possible characters (26 + 26 + 10 + 25 symbols), so each character adds about 6.4 bits. The tool labels the result:
| Entropy | Label | Roughly equivalent to |
|---|---|---|
| Under 50 bits | Weak | 7 or fewer random characters |
| 50–74 bits | Fair | 8–11 random characters |
| 75–99 bits | Strong | 12–15 random characters |
| 100+ bits | Very strong | 16+ random characters |
These numbers only apply to random passwords. A human-chosen password like Tr0ub4dor&3 has far less real entropy than its length suggests, because cracking tools know the substitution tricks people use.
How long should a password be?
- Accounts in a password manager: 20 characters or more. You'll never type it, so there's no reason to go short.
- Passwords you must type occasionally: 16 characters with look-alikes avoided.
- Wi-Fi passwords: 16–20 characters, symbols optional, look-alikes avoided — people will type it on phones and TVs.
- Your password manager's master password: consider a long passphrase of five or more random words instead, which is easier to type and remember.
Current guidance from security bodies such as NIST favours length over complexity rules and recommends against forcing periodic changes unless there's evidence of compromise.
Mistakes to avoid
- Reusing passwords. One breached site then exposes every account using that password. Uniqueness matters more than cleverness.
- Predictable patterns. Capitalising the first letter and adding
1!to the end is the first thing cracking tools try. - Storing passwords in plain notes or spreadsheets. Use a password manager with a strong master password.
- Skipping two-factor authentication. Even a perfect password can be phished. Turn on 2FA wherever it's offered.
Related security tools
- MD5 & Hash Generator — create SHA-256 and other hashes of text.
- wp-config Salts — fresh random keys for WordPress sites.
- UUID Generator — random unique identifiers for apps and databases.
Frequently asked questions
Are generated passwords stored or sent anywhere?
No. They're created in your browser and never transmitted or saved — not even to your Toolbench account.
Is a 12-character password enough?
A truly random 12-character password using all character sets has about 77 bits of entropy, which rates as strong. Since a password manager can fill it in for you, going to 16 or 20 characters costs nothing and adds a large safety margin.
Do symbols make a password much stronger?
A little. Adding 25 symbols raises the possible characters from 62 to 87, adding about half a bit per character. Adding length helps far more: four extra characters add around 25 bits.
What does "avoid look-alikes" do?
It removes characters that are easy to confuse — l, 1, I, O, o, 0 and | — so a password can be read aloud or copied from paper without mistakes. It slightly lowers entropy, which the tool accounts for.
Should I change my passwords regularly?
Only if there's a reason, such as a breach notification. Forced periodic changes tend to push people toward predictable patterns, and current guidance recommends against them.
More guides
- How to Compress Images Without Losing Visible QualityShrink image files for faster sites and smaller emails: the right format, quality and size to use, plus a free compressor that never uploads your photos.
- How to Convert Text Case Online (UPPERCASE, camelCase, More)Convert text into UPPERCASE, Title Case, camelCase, snake_case, kebab-case, CONSTANT_CASE and more at once, with real, verified examples of each.
- How to Count Words and Characters Online (and Hit Every Length Limit)How word, character, sentence and reading-time counts work, the length limits that matter, and a free counter that updates as you type.